Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

NIST CSF v2.0

70 controls
70 checks mapped

The NIST Cybersecurity Framework (CSF) organizes security activities around its core functions — Identify, Protect, Detect, Respond, and Recover.

Controls assessed

Detect (DE) - Continuous Monitoring (CM) - DE.CM-013

Networks and network services are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) - DE.CM-021

The physical environment is monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) - DE.CM-033

Personnel activity and technology usage are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) - DE.CM-061

External service provider activities and services are monitored to find potentially adverse events.

Detect (DE) - Continuous Monitoring (CM) - DE.CM-091

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-023

Potentially adverse events are analyzed to better understand associated activities.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-031

Information is correlated from multiple sources.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-041

The estimated impact and scope of adverse events are understood.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-061

Information on adverse events is provided to authorized staff and tools.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-071

Cyber threat intelligence and other contextual information are integrated into the analysis.

Detect (DE) - Adverse Event Analysis (AE) - DE.AE-081

Incidents are declared when adverse events meet the defined incident criteria.

Govern (GV) - Organizational Context (OC) - GV.OC-026

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.

Govern (GV) - Organizational Context (OC) - GV.OC-037

Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.

Govern (GV) - Risk Management Strategy (RM) - GV.RM-035

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-015

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-022

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.

Govern (GV) - Roles, Responsibilities, and Authorities (RR) - GV.RR-042

Cybersecurity is included in human resources practices.

Govern (GV) - Cybersecurity Supply Chain Risk Management (SC) - GV.SC-022

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally.

Identify (ID) - Asset Management (AM) - ID.AM-012

Inventories of hardware managed by the organization are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-027

Inventories of software, services, and systems managed by the organization are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-037

Representations of the organization's authorized network communication and internal and external network data flows are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-054

Assets are prioritized based on classification, criticality, resources, and impact on the mission.

Identify (ID) - Asset Management (AM) - ID.AM-072

Inventories of data and corresponding metadata for designated data types are maintained.

Identify (ID) - Asset Management (AM) - ID.AM-085

Systems, hardware, software, services, and data are managed throughout their life cycles.

Identify (ID) - Risk Assessment (RA) - ID.RA-014

Vulnerabilities in assets are identified, validated, and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-033

Internal and external threats to the organization are identified and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-041

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.

Identify (ID) - Risk Assessment (RA) - ID.RA-052

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.

Identify (ID) - Risk Assessment (RA) - ID.RA-081

Processes for receiving, analyzing, and responding to vulnerability disclosures are established.

Identify (ID) - Risk Assessment (RA) - ID.RA-092

The authenticity and integrity of hardware and software are assessed prior to acquisition and use.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-017

Identities and credentials for authorized users, services, and hardware are managed by the organization.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-022

Identities are proofed and bound to credentials based on the context of interactions.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-033

Users, services, and hardware are authenticated.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-043

Identity assertions are protected, conveyed, and verified.

Protect (PR) - Identity Management, Authentication, and Access Control (AA) - PR.AA-052

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.

Protect (PR) - Data Security (DS) - PR.DS-014

The confidentiality, integrity, and availability of data-at-rest are protected.

Protect (PR) - Data Security (DS) - PR.DS-025

The confidentiality, integrity, and availability of data-in-transit are protected.

Protect (PR) - Data Security (DS) - PR.DS-112

Backups of data are created, protected, maintained, and tested.

Protect (PR) - Platform Security (PS) - PR.PS-015

Configuration management practices are established and applied.

Protect (PR) - Platform Security (PS) - PR.PS-023

Software is maintained, replaced, and removed commensurate with risk.

Protect (PR) - Platform Security (PS) - PR.PS-032

Hardware is maintained, replaced, and removed commensurate with risk.

Protect (PR) - Platform Security (PS) - PR.PS-045

Log records are generated and made available for continuous monitoring.

Protect (PR) - Platform Security (PS) - PR.PS-051

Installation and execution of unauthorized software are prevented.

Protect (PR) - Platform Security (PS) - PR.PS-062

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-013

Networks and environments are protected from unauthorized logical access and usage.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-022

The organization's technology assets are protected from environmental threats.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-032

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations.

Protect (PR) - Technology Infrastructure Resilience (IR) - PR.IR-041

Adequate resource capacity to ensure availability is maintained.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-012

The recovery portion of the incident response plan is executed once initiated from the incident response process.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-022

Recovery actions are selected, scoped, prioritized, and performed.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-034

The integrity of backups and other restoration assets is verified before using them for restoration.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-041

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-051

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.

Recover (RC) - Incident Recovery Plan Execution (RP) - RC.RP-061

The end of incident recovery is declared based on criteria, and incident-related documentation is completed.

Recover (RC) - Incident Recovery Communication (RC) RC.CO-033

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.

Recover (RC) - Incident Recovery Communication (RC) RC.CO-041

Public updates on incident recovery are shared using approved methods and messaging.

Respond (RS) - Incident Management (MA) - RS.MA-013

The incident response plan is executed in coordination with relevant third parties once an incident is declared.

Respond (RS) - Incident Management (MA) - RS.MA-021

Incident reports are triaged and validated.

Respond (RS) - Incident Management (MA) - RS.MA-031

Incidents are categorized and prioritized.

Respond (RS) - Incident Management (MA) - RS.MA-041

Incidents are escalated or elevated as needed.

Respond (RS) - Incident Management (MA) - RS.MA-051

The criteria for initiating incident recovery are applied.

Respond (RS) - Incident Analysis (AN) - RS.AN-031

Analysis is performed to establish what has taken place during an incident and the root cause of the incident.

Respond (RS) - Incident Analysis (AN) - RS.AN-064

Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved.

Respond (RS) - Incident Analysis (AN) - RS.AN-071

Incident data and metadata are collected, and their integrity and provenance are preserved.

Respond (RS) - Incident Analysis (AN) - RS.AN-081

An incident's magnitude is estimated and validated.

Respond (RS) - Incident Response Reporting and Communication (CO) - RS.CO-021

Internal and external stakeholders are notified of incidents.

Respond (RS) - Incident Response Reporting and Communication (CO) - RS.CO-031

Information is shared with designated internal and external stakeholders.

Respond (RS) - Incident Mitigation (MI) - RS.MI-011

Incidents are contained.

Respond (RS) - Incident Mitigation (MI) - RS.MI-021

Incidents are eradicated.

ID.IM-021

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.