AWS Well-Architected Security Pillar
Security Foundations

AWS Well-Architected Security Pillar SEC01-BP03: Identify and validate control objectives

Derive control objectives from compliance, regulatory and business requirements, document them, and trace each to implemented AWS controls with measurable validation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 52 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • PL-10 Baseline Selection. Select a control baseline for the system
  • PL-2 System Security and Privacy Plans
  • SI-6 Security and Privacy Function Verification (SI-6)

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • PL-10 Baseline Selection. Select a control baseline for the system
  • PL-2 System Security and Privacy Plans
  • SI-6 Security and Privacy Function Verification (SI-6)

HIPAA Security Rule · 4 controls

ISO 27001:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.26 Application security requirements

NIST SP 800-171 Rev 3 · 4 controls

CMMC 2.0 · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • ASBv3-GS-10 Define and implement DevOps security strategy
  • ASBv3-GS-5 Define and implement security posture management strategy

C5 (Germany) · 2 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-OIS-07 Application of the Risk Management Policy

ISO 27701:2019 · 2 controls

  • 6.15.1 Compliance with legal and contractual requirements
  • 6.2.1 Management direction for information security
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

ISO 27002:2022 · 1 control

  • 5.31 Legal, statutory, regulatory and contractual requirements

ISO/IEC 42001:2023 · 1 control

  • A.6.1.2 Objectives for responsible development of AI system

NIST SP 800-218 · 1 control

PCI DSS 4.0 · 1 control

  • 12.5.2 12.5.2 Annual and change-driven scope confirmation

SOC 2 · 1 control

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security Foundations

You are reading one control. How much of AWS Well-Architected Security Pillar have you already done?

AWS Well-Architected Security Pillar SEC01-BP03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of AWS Well-Architected Security Pillar your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 52 of 63 AWS Well-Architected Security Pillar controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 52 it maps to, and the evidence behind each claim, over MCP and REST.