Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

HIPAA HITRUST 9.2
HIPAA safeguards the confidentiality, integrity, and availability of electronic protected health information (ePHI) handled by covered entities and business associates.
Controls assessed
To determine a business partner's access when discretion is allowed as defined by the organization and by employing manual processes or automated mechanisms to assist users in making information sharing/collaboration decisions.
The allocation and use of privileges to information systems and services shall be restricted and controlled. Special attention shall be given to the allocation of privileged access rights, which allow users to override system controls. Only after the organization assesses the contractor's ability to comply with its security requirements and the contractor agrees to comply.
Anti-virus and anti-spyware are installed, operating and updated on all end-user devices to conduct periodic scans of the systems to identify and remove unauthorized software. Server environments for which the server software developer specifically recommends not installing host-based anti-virus and anti-spyware software may address the requirement via a network-based malware detection (NBMD) solution.
The organization, based on the data classification level, registers media (including laptops) prior to use, places reasonable restrictions on how such media be used, and provides an appropriate level of physical and logical protection (including encryption) for media containing covered information until properly destroyed or sanitized.
The organization restricts the use of writable removable media and personally-owned removable media in organizational systems.
Access to the organizations information and systems by external parties is not permitted until due diligence has been conducted, the appropriate controls have been implemented, and a contract/agreement reflecting the security requirements is signed acknowledging they understand and accept their obligations.
Only authorized administrators are allowed to implement approved upgrades to software, applications, and program libraries, based on business requirements and the security implications of the release.
Managers responsible for application systems are also responsible for the strict control (security) of the project or support environment and ensure that all proposed system changes are reviewed to check that they do not compromise the security of either the system or the operating environment.
The organization formally addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance for configuration management.
The organization has developed, documented, and implemented a configuration management plan for the information system.
Changes are formally controlled, documented and enforced in order to minimize the corruption of information systems.
Installation checklists and vulnerability scans are used to validate the configuration of servers, workstations, devices and appliances and ensure the configuration meets minimum standards.
Where development is outsourced, change control procedures to address security are included in the contract(s) and specifically require the developer to track security flaws and flaw resolution within the system, component, or service and report findings to organization-defined personnel or roles.
The organization does not use automated updates on critical systems.
The organization develops, documents, and maintains, under configuration control, a current baseline configuration of the information system, and reviews and updates the baseline as required.
The organization (i) establishes and documents mandatory configuration settings for information technology products employed within the information system using the latest security configuration baselines; (ii) identifies, documents, and approves exceptions from the mandatory established configuration settings for individual components based on explicit operational requirements; and (iii) monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.
The organization employs automated mechanisms to (i) centrally manage, apply, and verify configuration settings; (ii) respond to unauthorized changes to network and system security-related configuration settings; and (iii) enforce access restrictions and auditing of the enforcement actions.
Cloud service providers use an industry-recognized virtualization platform and standard virtualization formats (e.g., Open Virtualization Format, OVF) to help ensure interoperability, and has documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review.
The organization's security gateways (e.g. firewalls) enforce security policies and are configured to filter traffic between domains, block unauthorized access, and are used to maintain segregation between internal wired, internal wireless, and external network segments (e.g., the Internet) including DMZs and enforce access control policies for each of the domains.
The organizations network is logically and physically segmented with a defined security perimeter and a graduated set of controls, including subnetworks for publicly accessible system components that are logically separated from the internal network, based on organizational requirements; and traffic is controlled based on functionality required and classification of the data/systems based on a risk assessment and their respective security requirements.
Network traffic is controlled in accordance with the organizations access control policy through firewall and other network-related restrictions for each network access point or external telecommunication service's managed interface.
Transmitted information is secured and, at a minimum, encrypted over open, public networks.
Exceptions to the traffic flow policy are documented with a supporting mission/business need, duration of the exception, and reviewed at least annually; traffic flow policy exceptions are removed when no longer supported by an explicit mission/business need.
Remote devices establishing a non-remote connection are not allowed to communicate with external (remote) resources.
The ability of users to connect to the internal network is restricted using a deny-by-default and allow-by-exception policy at managed interfaces according to the access control policy and the requirements of clinical and business applications.
Agreed services provided by a network service provider/manager are formally managed and monitored to ensure they are provided securely.
The organization formally authorizes and documents the characteristics of each connection from an information system to other information systems outside the organization. The organization formally authorizes and documents the characteristics of each connection from an information system to other information systems outside the organization.
Formal agreements with external information system providers include specific obligations for security and privacy.
The organization monitors for all authorized and unauthorized wireless access to the information system and prohibits installation of wireless access points (WAPs) unless explicitly authorized in writing by the CIO or his/her designated representative.
To identify and authenticate devices on local and/or wide area networks, including wireless networks, the information system uses either a (i) shared known information solution or (ii) an organizational authentication solution, the exact selection and strength of which is dependent on the security categorization of the information system.
The organization ensures information systems protect the confidentiality and integrity of transmitted information, including during preparation for transmission and during reception.
The organization builds a firewall configuration that restricts connections between un-trusted networks and any system components in the covered information environment; and any changes to the firewall configuration are updated in the network diagram.
Usage restrictions and implementation guidance are formally defined for VoIP, including the authorization and monitoring of the service.
The organization (i) authorizes connections from the information system to other information systems outside of the organization through the use of interconnection security agreements or other formal agreement; (ii) documents each connection, the interface characteristics, security requirements, and the nature of the information communicated; (iii) employs a deny all, permit by exception policy for allowing connections from the information system to other information systems outside of the organization; and (iv) applies a default-deny rule that drops all traffic via host-based firewalls or port filtering tools on its endpoints (workstations, servers, etc.), except those services and ports that are explicitly allowed.
The organization describes the groups, roles, and responsibilities for the logical management of network components and ensures coordination of and consistency in the elements of the network infrastructure.
The organization builds a firewall configuration to restrict inbound and outbound traffic to that which is necessary for the covered data environment.
The router configuration files are secured and synchronized.
Access to all proxies is denied, except for those hosts, ports, and services that are explicitly required.
Authoritative DNS servers are segregated into internal and external roles.
The organization reviews and updates the interconnection security agreements on an ongoing basis verifying enforcement of security requirements.
The organization employs and documents in a formal agreement or other document, either i) allow-all, deny-by-exception, or, ii) deny-all, permit-by-exception (preferred), policy for allowing specific information systems to connect to external information systems.
The organization requires external/outsourced service providers to identify the specific functions, ports, and protocols used in the provision of the external/outsourced services.
The contract with the external/outsourced service provider includes the specification that the service provider is responsible for the protection of covered information shared.
Networks are segregated from production-level networks when migrating physical servers, applications or data to virtualized servers.
Ensure the protection of information in networks and protection of the supporting network infrastructure.
The organization formally addresses multiple safeguards before allowing the use of information systems for information exchange.
Remote (external) access to the organization's information assets and access to external information assets (for which the organization has no control) is based on clearly defined terms and conditions.
Cryptography is used to protect the confidentiality and integrity of remote access sessions to the internal network and to external systems.
Strong cryptography protocols are used to safeguard covered information during transmission over less trusted / open public networks.
The organization limits the use of organization-controlled portable storage media by authorized individuals on external information systems.
The information system prohibits remote activation of collaborative computing devices and provides an explicit indication of use to users physically present at the devices.
The organization verifies every ninety (90) days for each extract of covered information recorded that the data is erased or its use is still required.
The organization ensures the storage of the transaction details are located outside of any publicly accessible environments (e.g., on a storage platform existing on the organization's intranet) and not retained and exposed on a storage medium directly accessible from the Internet.
Where a trusted authority is used (e.g., for the purposes of issuing and maintaining digital signatures and/or digital certificates), security is integrated and embedded throughout the entire end-to-end certificate/signature management process.
The protocols used for communications are enhanced to address any new vulnerability, and the updated versions of the protocols are adopted as soon as possible.
Cloud service providers use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved.
The information system employs replay-resistant authentication mechanisms such as nonce, one-time passwords, or time stamps to secure network access for privileged accounts; and, for hardware token-based authentication, employs mechanisms that satisfy minimum token requirements discussed in NIST SP 800-63-2, Electronic Authentication Guideline.
Multi-factor authentication methods are used in accordance with organizational policy, (e.g., for remote network access).
The organization explicitly authorizes access to specific security relevant functions (deployed in hardware, software, and firmware) and security-relevant information.
Role-based access control is implemented and capable of mapping each user to one or more roles, and each role to one or more system functions.
The organization promotes the development and use of programs that avoid the need to run with elevated privileges and system routines to avoid the need to grant privileges to users.
Elevated privileges are assigned to a different user ID from those used for normal business use, all users access privileged services in a single role, and such privileged access is minimized.
The organization restricts access to privileged functions and all security-relevant information.
The organization limits authorization to privileged accounts on information systems to a pre-defined subset of users.
The organization audits the execution of privileged functions on information systems and ensures information systems prevent non-privileged users from executing privileged functions.
All file system access not explicitly required is disabled, and only authorized users are permitted access to only that which is expressly required for the performance of the users' job duties.
Ports, services, and similar applications installed on a computer or network systems, which are not specifically required for business functionality, are disabled or removed.
The organization reviews the information system within every three hundred and sixty-five (365) days to identify and disables unnecessary and non-secure functions, ports, protocols, and/or services.
The activities of privileged users (administrators, operators, etc.) include the success/failure of the event, time the event occurred, the account involved, the processes involved, and additional information about the event.
Logs of messages sent and received are maintained including the date, time, origin and destination of the message, but not its contents.
Audit records are retained for 90 days and older audit records are archived for one year.
Audit logs are maintained for management activities, system and application startup/shutdown/errors, file changes, and security policy changes.
The information system generates audit records containing the following detailed information: filename accessed, program or command used to initiate the event and source and destination addresses.
The organization shall periodically test its monitoring and detection processes, remediate deficiencies, and improve its processes.
The organization verifies every ninety (90) days for each extract of covered information recorded that the data is erased or its use is still required.
Automated systems deployed throughout the organization's environment are used to monitor key events and anomalous activity, and analyze system logs, the results of which are reviewed regularly.
Alerts are generated for technical personnel to analyze and investigate suspicious activity or suspected violations.
Monitoring includes inbound and outbound communications and file integrity monitoring.
Separation of duties is used to limit the risk of unauthorized or unintentional modification of information and systems.
No single person is able to access, modify, or use information systems without authorization or detection.
Access for individuals responsible for administering access controls is limited to the minimum necessary based upon each user's role and responsibilities and these individuals cannot access audit functions related to these controls.
The initiation of an event is separated from its authorization to reduce the possibility of collusion.
Ensure the exchange of information within an organization and with any external entity is secured and protected, and carried out in compliance with relevant legislation and exchange agreements.
The organization obtains satisfactory assurances that reasonable information security exists across their information supply chain by performing an annual review, which includes all partners/third party-providers upon which their information supply chain depends.
Cloud service providers design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain.
Backup copies of information and software are made and tests of the media and restoration procedures are regularly performed at appropriate intervals.
A formal definition of the level of backup required for each system is defined and documented including how each system will be restored, the scope of data to be imaged, frequency of imaging, and duration of retention based on relevant contractual, legal, regulatory and business requirements.
The backups are stored in a physically secure remote location, at a sufficient distance to make them reasonably immune from damage to data at the primary site, and reasonable physical and environmental controls are in place to ensure their protection at the remote location.
Inventory records for the backup copies, including content and current location, are maintained.
When the backup service is delivered by the third party, the service level agreement includes the detailed protections to control confidentiality, integrity and availability of the backup information.
Automated tools are used to track all backups.
The integrity and security of the backup copies are maintained to ensure future availability, and any potential accessibility problems with the backup copies are identified and mitigated in the event of an area-wide disaster.
Covered information is backed-up in an encrypted format to ensure confidentiality.
The organization performs incremental or differential backups daily and full backups weekly to separate media.
Three (3) generations of backups (full plus all related incremental or differential backups) are stored off-site, and both on-site and off-site backups are logged with name, date, time and action.
The organization ensures a current, retrievable copy of covered information is available before movement of servers.
The organization tests backup information following each backup to verify media reliability and information integrity, and at least annually thereafter.
Information security aspects of business continuity are (i) based on identifying events (or sequence of events) that can cause interruptions to the organization's critical business processes (e.g., equipment failure, human errors, theft, fire, natural disasters acts of terrorism); (ii) followed by a risk assessment to determine the probability and impact of such interruptions, in terms of time, damage scale and recovery period; (iii) based on the results of the risk assessment, a business continuity strategy is developed to identify the overall approach to business continuity; and (iv) once this strategy has been created, endorsement is provided by management, and a plan created and endorsed to implement this strategy.
Business impact analysis are used to evaluate the consequences of disasters, security failures, loss of service, and service availability.
Privileges are formally authorized and controlled, allocated to users on a need-to-use and event-by-event basis for their functional role (e.g., user or administrator), and documented for each system product/element.
The access control system for the system components storing, processing or transmitting covered information is set with a default 'deny-all' setting.
Controls for the access to diagnostic and configuration ports include the use of a key lock and the implementation of supporting procedures to control physical access to the port.
Access to management functions or administrative consoles for systems hosting virtualized systems are restricted to personnel based upon the principle of least privilege and supported through technical controls.
Network equipment is checked for unanticipated dial-up capabilities.
Unauthorized remote connections to the information systems are monitored and reviewed at least quarterly, and appropriate action is taken if an unauthorized connection is discovered.
Remote access to business information across public networks only takes place after successful identification and authentication.
The information system monitors and controls remote access methods.
Access to network equipment is physically protected.
A secure audit record is created for all activities on the system (create, read, update, delete) involving covered information.
Audit records include the unique user ID, unique data subject ID, function performed, and date/time the event was performed.
All disclosures of covered information within or outside of the organization are logged including type of disclosure, date/time of the event, recipient, and sender.
The organization monitors the information system to identify irregularities or anomalies that are indicators of a system malfunction or compromise and help confirm the system is functioning in an optimal, resilient and secure state.
The organization specifies how often audit logs are reviewed, how the reviews are documented, and the specific roles and responsibilities of the personnel conducting the reviews, including the professional certifications or other qualifications required.
All applicable legal requirements related to monitoring authorized access and unauthorized access attempts are met.
Monitoring includes privileged operations, authorized access or unauthorized access attempts, including attempts to access deactivated accounts, and system alerts or failures.
Auditing and monitoring systems employed by the organization support audit reduction and report generation.
Automated systems are used to review monitoring activities of security systems (e.g., IPS/IDS) and system records on a daily basis, and identify and document anomalies.
The information system is able to automatically process audit records for events of interest based on selectable criteria.
The organization ensures proper logging is enabled in order to audit administrator activities; and reviews system administrator and operator logs on a regular basis.
An intrusion detection system managed outside of the control of system and network administrators is used to monitor system and network administration activities for compliance.
The organization identifies the critical business processes requiring business continuity.
Business continuity risk assessments (i) are carried out annually with full involvement from owners of business resources and processes; (ii) consider all business processes and is not limited to the information assets, but includes the results specific to information security; and (iii) identifies, quantifies, and prioritizes risks against key business objectives and criteria relevant to the organization, including critical resources, impacts of disruptions, allowable outage times, and recovery priorities.
The organization formally manages equipment on the network, including equipment in user areas.
The organization protects and controls media containing sensitive information during transport outside of controlled areas.
Technical vulnerabilities are identified, evaluated for risk and corrected in a timely manner.
A hardened configuration standard exists for all system and network components.
A technical vulnerability management program is in place to monitor, assess, rank, and remediate vulnerabilities identified in systems.
The organization conducts an enterprise security posture review as needed but no less than once within every three-hundred-sixty-five (365) days, in accordance with organizational IS procedures.
The organization updates the list of information system vulnerabilities scanned within every thirty (30) days or when new vulnerabilities are identified and reported.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
