Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

FedRAMP High

43 controls
183 checks mapped

FedRAMP standardizes the security assessment, authorization, and continuous monitoring of cloud services used by U.S. federal agencies.

Controls assessed

Access Control (AC) - Account Management (AC-2)20

Manage system accounts, group memberships, privileges, workflow, notifications, deactivations, and authorizations.

Access Control (AC) - Account Management (AC-2) - Automated System Account Management AC-2(1)2

Support the management of system accounts using \[Assignment: organization-defined automated mechanisms\].

Access Control (AC) - Account Management (AC-2) - Account Monitoring AC-2(12)8

Monitors and reports atypical usage of information system accounts to organization-defined personnel or roles.

Access Control (AC) - Account Management (AC-2) - Role-Based Schemes AC-2(7)2

The organization: Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles; Monitors privileged role assignments; and Takes \[Assignment: organization-defined actions\] when privileged role assignments are no longer appropriate.

Access Control (AC) - Access Enforcement (AC-3)11

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Access Control (AC) - Information Flow Enforcement (AC-4)45

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on \[Assignment: organization-defined information flow control policies\].

Access Control (AC) - Separation Of Duties (AC-5)1

Separate duties of individuals to prevent malevolent activity. automate separation of duties and access authorizations.

Access Control (AC) - Least Privilege (AC-6)2

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Access Control (AC) - Least Privilege (AC-6) - Review Of User Privileges AC-6(7)2

Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.

Access Control (AC) - Remote Access (AC-17)34

Authorize remote access systems prior to connection. Enforce remote connection requirements to information systems.

Access Control (AC) - Remote Access (AC-17) - Automated Monitoring / Control AC-17(1)29

Employ automated mechanisms to monitor and control remote access methods.

Audit And Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6)27

Integrate audit review, analysis, and reporting with processes for investigation and response to suspicious activities.

Audit And Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - Central Review And Analysis AU-6(4)23

Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.

Audit And Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - Integration / Scanning And Monitoring Capabilities AU-6(5)23

Integrate analysis of audit records with analysis of \[Selection (one or more): vulnerability scanning information; performance data; system monitoring information; \[Assignment: organization-defined data/information collected from other sources\]\] to further enhance the ability to identify inappropriate or unusual activity.

Audit And Accountability (AU) - Audit Generation (AU-12)31

Audit events defined in AU-2. Allow trusted personnel to select which events to audit. Generate audit records for events.

Audit And Accountability (AU) - Audit Generation (AU-12) - System-Wide / Time-Correlated Audit Trail AU-12(1)23

Compile audit records from \[Assignment: organization-defined system components\] into a system-wide (logical or physical) audit trail that is time-correlated to within \[Assignment: organization-defined level of tolerance for the relationship between time stamps of individual records in the audit trail\].

Configuration Management (CM) - Configuration Settings (CM-6)9

The organization: (i) establishes mandatory configuration settings for information technology products employed within the information system; (ii) configures the security settings of information technology products to the most restrictive mode consistent with operational requirements; (iii) documents the configuration settings; and (iv) enforces the configuration settings in all components of the information system.

Configuration Management (CM) - Least Functionality (CM-7)1

The organization configures the information system to provide only essential capabilities and prohibits or restricts the use of the functions, ports, protocols, and/or services.

Contingency Planning (CP) - Alternate Storage Sites (CP-6)6

a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and b. Ensure that the alternate storage site provides controls equivalent to that of the primary site.

Contingency Planning (CP) - Alternate Storage Sites (CP-6) - Separation From Primary Site CP-6(1)6

Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.

Contingency Planning (CP) - System Backup (CP-9)6

a. Conduct backups of user-level information contained in \[Assignment: organization-defined system components\] \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\]; b. Conduct backups of system-level information contained in the system \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\]; c. Conduct backups of system documentation, including security- and privacy-related documentation \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\]; and d. Protect the confidentiality, integrity, and availability of backup information.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2)4

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

Identification and Authentication (IA) - Identifier Management (IA-4)4

Manage information system identifiers for users and devices. Automate authorizing and disabling users to prevent misuse.

Identification and Authentication (IA) - Authenticator Management (IA-5)8

Authenticate users and devices. Automate administrative control. Enforce restrictions. Protect against unauthorized use.

Identification and Authentication (IA) - Authenticator Management (IA-5) - Password-Based Authentication IA-5(1)4

The information system, for password-based authentication that enforces minimum password complexity, stores and transmits only cryptographically-protected passwords, enforces password minimum and maximum lifetime restrictions, prohibits password reuse, allows the use of a temporary password for system logons with an immediate change to a permanent password etc.

Incident Response (IR) - Incident Handling (IR-4)11

a. Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery;b. Coordinate incident handling activities with contingency planning activities; c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and d. Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.

Incident Response (IR) - Incident Monitoring (IR-5)11

Track incidents and collect and analyze incident information using \[Assignment: organization-defined automated mechanisms\].

Risk Assessment (RA) - Vulnerability Scanning (RA-5)13

Scan for system vulnerabilities. Share vulnerability information and security controls that eliminate vulnerabilities.

System and Communications Protection (SC) - Security Function Isolation (SC-3)2

Isolate security functions from nonsecurity functions.

System and Communications Protection (SC) - Denial Of Service Protection (SC-5)3

The information system protects against or limits the effects of the following types of denial of service attacks: \[Assignment: organization-defined types of denial of service attacks or references to sources for such information\] by employing \[Assignment: organization-defined security safeguards\].

System and Communications Protection (SC) - Boundary Protection (SC-7)45

The information system: a. Monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; b. Implements subnetworks for publicly accessible system components that are \[Selection: physically; logically\] separated from internal organizational networks; and c. Connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

System and Communications Protection (SC) - Boundary Protection (SC-7) - Access Points SC-7(3)39

The organization limits the number of external network connections to the information system.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8)13

The information system protects the \[Selection (one or more): confidentiality; integrity\] of transmitted information.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - Cryptographic Or Alternate Physical Protection SC-8(1)11

The information system implements cryptographic mechanisms to \[Selection (one or more): prevent unauthorized disclosure of information; detect changes to information\] during transmission unless otherwise protected by \[Assignment: organization-defined alternative physical safeguards\].

System and Communications Protection (SC) - Cryptographic Key Establishment And Management (SC-12)23

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with \[Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction\].

System and Communications Protection (SC) - Protection Of Information At Rest (SC-28)13

The information system protects the \[Selection (one or more): confidentiality; integrity\] of \[Assignment: organization-defined information at rest\].

System and Communications Protection (SC) - Protection Of Information At Rest (SC-28) - Cryptographic Protection SC-28(1)11

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on \[Assignment: organization-defined system components or media\]: \[Assignment: organization-defined information\].

System and Information Integrity (SI) - Flaw Remediation (SI-2)13

The organization: a.Identifies, reports, and corrects information system flaws; b.Tests software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c.Installs security-relevant software and firmware updates within \[Assignment: organization-defined time period\] of the release of the updates; and d.Incorporates flaw remediation into the organizational configuration management process.

System and Information Integrity (SI) - Malicious Code Protection (SI-3)2

Implement \[Assignment (one or more): signature based, non-signature based\] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures;

System and Information Integrity (SI) - Malicious Code Protection (SI-3) - Central Management SI-3(1)2
System and Information Integrity (SI) - Information System Monitoring (SI-4)18

The organization: a.Monitors the information system to detect: 1. Attacks and indicators of potential attacks in accordance with \[Assignment: organization-defined monitoring objectives\]; and 2.Unauthorized local, network, and remote connections; b. Identifies unauthorized use of the information system through \[Assignment: organization-defined techniques and methods\]; c. Deploys monitoring devices: 1. Strategically within the information system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion; e. Heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information; f. Obtains legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations; and g. Provides \[Assignment: organization-defined information system monitoring information\] to \[Assignment: organization-defined personnel or roles\] \[Selection (one or more): as needed; \[Assignment: organization-defined frequency\]\].

System and Information Integrity (SI) - Memory Protection (SI-16)2
Alternate Processing Site (CP-7)1

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.