Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Google Cloud logo

NIST CSF v1.0

16 controls
61 checks mapped

The NIST Cybersecurity Framework (CSF) organizes security activities around its core functions — Identify, Protect, Detect, Respond, and Recover.

Controls assessed

ID.AM-1 - Physical devices and systems within the organization are inventoried.1

Physical devices and systems within the organization are inventoried.

PR.AC-1 - Identities and credentials are issued, managed, verified, revoked, and audited2

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes.

PR.AC-4 - Access permissions and authorizations are managed15

Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.

PR.DS-1 - Data-at-rest is protected.6

Data-at-rest is protected.

PR.DS-2 - Data-in-transit is protected.1

Data-in-transit is protected.

PR.DS-3 - Assets are formally managed throughout removal, transfers, and disposition.1

Assets are formally managed throughout removal, transfers, and disposition.

PR.IP-1 - Baseline configuration maintained with security principles9

A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality).

PR.IP-2 - SDLC to manage systems is implemented3

A System Development Life Cycle to manage systems is implemented.

PR.IP-4 - Backups of information are conducted, maintained, and tested.1

Backups of information are conducted, maintained, and tested.

PR.PT-1 - Audit/log records are determined, documented, implemented, and reviewed12

Audit/log records are determined, documented, implemented, and reviewed in accordance with policy.

PR.PT-3 - Least functionality is incorporated1

The principle of least functionality is incorporated by configuring systems to provide only essential capabilities.

DE.AE-2 - Detected events are analyzed to understand attack targets and methods.2

Detected events are analyzed to understand attack targets and methods.

DE.AE-3 - Event data are collected and correlated from multiple sources and sensors.20

Event data are collected and correlated from multiple sources and sensors.

DE.CM-1 - The network is monitored to detect potential cybersecurity events.11

The network is monitored to detect potential cybersecurity events.

RS.AN-1 - Notifications from detection systems are investigated.2

Notifications from detection systems are investigated.

RS.CO-1 - Personnel know their roles and order of operations when a response is needed.1

Personnel know their roles and order of operations when a response is needed.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.