Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

NIST SP 800-53 Rev. 5

48 controls
201 checks mapped

NIST SP 800-53 provides a comprehensive catalog of security and privacy controls for federal information systems and the organizations that operate them.

Controls assessed

Access Control (AC) - Account Management (AC-2)22

Manage system accounts, group memberships, privileges, workflow, notifications, deactivations, and authorizations.

Access Control (AC) - Account Management (AC-2) - Automated System Account Management AC-2(1)3

The organization employs automated mechanisms to support the management of information system accounts.

Access Control (AC) - Account Management (AC-2) - Privileged User Accounts AC-2(7)4

The organization establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles, monitors privileged role assignments, and takes organization-defined actions when privileged role assignments are no longer appropriate.

Access Control (AC) - Account Management (AC-2) - Account Monitoring for Atypical Usage AC-2(12)8

The organization monitors information system accounts for organization-defined atypical use and reports atypical usage of information system accounts to organization-defined personnel or roles.

Access Control (AC) - Access Enforcement (AC-3)12

Enforce approved authorizations for access to systems in accordance with policy.

Access Control (AC) - Access Enforcement (AC-3) - Role-based Access Control AC-3(7)1

The information system enforces a role-based access control policy over defined subjects and objects and controls access based upon organization-defined roles and users authorized to assume such roles.

Access Control (AC) - Information Flow Enforcement (AC-4)51

Enforce approved authorizations. Control information workflow between interconnected systems.

Access Control (AC) - Separation of Duties (AC-5)1

Separate duties of individuals to prevent malevolent activity. automate separation of duties and access authorizations.

Access Control (AC) - Least Privilege (AC-6)2

Automate least privilege. Allow only authorized accesses for users and processes which are necessary.

Access Control (AC) - Least Privilege (AC-6) - Review of User Privileges AC-6(7)2

The organization reviews organization-defined frequency the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges and reassigns or removes privileges, if necessary, to correctly reflect organizational mission/business needs.

Access Control (AC) - Security and Privacy Attributes (AC-16)2

Support and maintains the binding of security attributes to information in storage, in process, and in transition.

Access Control (AC) - Remote Access (AC-17)37

Authorize remote access systems prior to connection. Enforce remote connection requirements to information systems.

Access Control (AC) - Remote Access (AC-17) - Monitoring and Control AC-17(1)31

The information system monitors and controls remote access methods.

Audit and Accountability Control (AU) - Audit Record Review, Analysis, and Reporting (AU-6)29

Integrate audit review, analysis, and reporting with processes for investigation and response to suspicious activities.

Audit and Accountability Control (AU) - Audit Record Review, Analysis, and Reporting (AU-6) - Central Review and Analysis AU-6(4)24

The information system provides the capability to centrally review and analyze audit records from multiple components within the system.

Audit and Accountability Control (AU) - Audit Record Review, Analysis, and Reporting (AU-6) - Integrated Analysis of Audit Records AU-6(5)24

The organization integrates analysis of audit records with analysis of vulnerable scanning information, performance data, and information system monitoring information collected from other sources to further enhance the ability to identify inappropriate or unusual activity.

Audit and Accountability Control (AU) - Audit Record Retention (AU-11)1

Retain audit records for security investigations. Meet regulatory and organizational data retention requirements.

Audit and Accountability Control (AU) - Audit Record Generation (AU-12)33

Audit events defined in AU-2. Allow trusted personnel to select which events to audit. Generate audit records for events.

Audit and Accountability Control (AU) - Audit Record Generation (AU-12) - System-wide and Time-correlated Audit Trail AU-12(1)24

The information system compiles audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within organization-defined level of tolerance for the relationship between timestamps of individual records in the audit trail.

Configuration Management (CM) - Configuration Settings (CM-6)9

The organization establishes and documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements; implements the configuration settings; identifies, documents, and approves any deviations from established configuration settings for organization-defined information system components based on organization-defined operational requirements; and monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.

Configuration Management (CM) - Least Functionality (CM-7)1

The organization configures the information system to provide only essential capabilities and prohibits or restricts the use of organization-defined prohibited or restricted functions, ports, protocols, and/or services.

Contingency Planning (CP) - Alternate Storage Site (CP-6)6

The organization establishes an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information and ensures that the alternate storage site provides information security safeguards equivalent to that of the primary site.

Contingency Planning (CP) - Alternate Storage Site (CP-6) - Separation from Primary Site CP-6(1)6

The organization identifies an alternate storage site that is separated from the primary storage site to reduce susceptibility to the same threats.

Contingency Planning (CP) - System Backup (CP-9)6

The organization conducts backups of information system documentation including security-related documentation, user-level and system-level information contained in the information system with recovery time and recovery point objectives, and protects the confidentiality, integrity, and availability of backup information at storage locations.

Identification and Authentication (IA) - Identification and Authentication (organizational Users) (IA-2)5

Identify and authenticate organization users and processes.

Identification and Authentication (IA) - Identifier Management (IA-4)5

Manage information system identifiers for users and devices. Automate authorizing and disabling users to prevent misuse.

Identification and Authentication (IA) - Authenticator Management (IA-5)8

Authenticate users and devices. Automate administrative control. Enforce restrictions. Protect against unauthorized use.

Identification and Authentication (IA) - Authenticator Management (IA-5) - Password-based Authentication IA-5(1)8

The information system, for password-based authentication, enforces minimum password complexity of organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type; enforces at least the organization-defined number of changed characters when new passwords are created; stores and transmits only cryptographically-protected passwords; enforces password minimum and maximum lifetime restrictions of organization-defined numbers for lifetime minimum, lifetime maximum; prohibits password reuse for organization-defined number generations; and allows the use of a temporary password for system logons with an immediate change to a permanent password.

Incident Response (IR) - Incident Handling (IR-4)13

The organization implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery; coordinates incident handling activities with contingency planning activities; and incorporates lessons learned from ongoing incident handling activities into incident response procedures, training, and testing/exercises, and implements the resulting changes accordingly.

Incident Response (IR) - Incident Monitoring (IR-5)13

The organization tracks and documents information system security incidents.

Incident Response (IR) - Vulnerabilities Related to Incidents IR-6(2)3

The organization reports information system vulnerabilities associated with reported security incidents to organization-defined personnel or roles.

Risk Assessment (RA) - Vulnerability Monitoring and Scanning (RA-5)15

Scan for system vulnerabilities. Share vulnerability information and security controls that eliminate vulnerabilities.

System and Communications Protection (SC) - Security Function Isolation (SC-3)2

The information system isolates security functions from nonsecurity functions.

System and Communications Protection (SC) - Denial-of-service Protection (SC-5)4

The information system protects against or limits the effects of the organization-defined types of denial of service attacks or reference to a source for such information by employing organization-defined security safeguards.

System and Communications Protection (SC) - Boundary Protection (SC-7)51

The information system monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; implements subnetworks for publicly accessible system components that are physically or logically separated from internal organizational networks; and connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

System and Communications Protection (SC) - Boundary Protection (SC-7) - Access Points SC-7(3)43

The organization limits the number of external network connections to the information system.

System and Communications Protection (SC) - Transmission Confidentiality and Integrity (SC-8)15

The information system protects the confidentiality and integrity of transmitted information.

System and Communications Protection (SC) - Transmission Confidentiality and Integrity (SC-8) - Cryptographic Protection SC-8(1) 12

The information system implements cryptographic mechanisms to prevent unauthorized disclosure of information and detect changes to information during transmission unless otherwise protected by organization-defined alternative physical safeguards.

System and Communications Protection (SC) - Cryptographic Key Establishment and Management (SC-12)26

The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with organization-defined requirements for key generation, distribution, storage, access, and destruction.

System and Communications Protection (SC) - Protection of Information at Rest (SC-28)12

The information system protects the confidentiality and integrity of organization-defined information at rest.

System and Communications Protection (SC) - Protection of Information at Rest (SC-28) - Cryptographic Protection SC-28(1)10

The information system implements cryptographic mechanisms to prevent unauthorized disclosure and modification of organization-defined information on organization-defined information system components.

System and Information Integrity (SI) - Flaw Remediation (SI-2)15

The organization identifies, reports, and corrects information system flaws, tests software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation, installs security-relevant software and firmware updates within the organization-defined time period of the release of the updates, and incorporates flaw remediation into the organizational configuration management process.

System and Information Integrity (SI) - Flaw Remediation (SI-2) - Removal of Previous Versions of Software and Firmware SI-2(6)3

The organization removes organization-defined software and firmware components after updated versions have been installed.

System and Information Integrity (SI) - Malicious Code Protection (SI-3)2

The organization employs malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code; updates malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures; addresses the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the information system; and configures malicious code protection mechanisms to perform periodic scans of the information system and real-time scans of files from external sources at an endpoint, network entry/exit points as the files are downloaded, opened, or executed in accordance with organizational security policy, and block and quarantine malicious code, send alert to the administrator and take organization-defined action in response to malicious code detection.

System and Information Integrity (SI) - System Monitoring (SI-4)22

The organization monitors the information system to detect attacks and indicators of potential attacks in accordance with organization-defined monitoring objectives and unauthorized local, network, and remote connections; identifies unauthorized use of the information system through organization-defined techniques and methods; deploys monitoring devices strategically within the information system to collect organization-determined essential information and at ad hoc locations within the system to track specific types of transactions of interest to the organization; protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion; heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information; obtains legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations; and provides organization-defined system monitoring information to organization-defined personnel or roles as needed.

System and Information Integrity (SI) - System Monitoring (SI-4) - Automated Organization-generated Alerts SI-4(12)2

The organization employs automated mechanisms to alert security personnel of the organization-defined activities that trigger alerts with security implications.

System and Information Integrity (SI) - Memory Protection (SI-16)2

The information system implements organization-defined security safeguards to protect its memory from unauthorized code execution.

Alternate Processing Site (CP-7)1

The organization establishes an alternate processing site including necessary agreements to permit the transfer and resumption of organization-defined information system operations for essential missions/business functions within an organization-defined time period consistent with recovery time and recovery point objectives when the primary processing capabilities are unavailable, ensures that equipment and supplies required to transfer and resume operations are available at the alternate processing site or contracts are in place to support delivery to the site within the organization-defined time period for transfer/resumption and ensure that the alternate processing site provides information security safeguards equivalent to that of the primary site.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.