ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linkerd) + east-west traffic inspection + zero trust network access (ZTNA) + identity-aware proxies + private endpoints (AWS PrivateLink + Azure Private Link + GCP Private Service Connect) + no public IP for sensitive workloads + bastion hosts + jump hosts + VPN/Direct Connect for hybrid + Cloud Network Architecture per JIS X 5051. (2) Container Security: Kubernetes hardening per CIS Kubernetes Benchmark + Pod Security Standards + RBAC + Network Policies + admission controllers (OPA Gatekeeper + Kyverno) + container image scanning + signed images (Cosign + Notary + Sigstore) + Software Bill of Materials (SBOM) per CycloneDX + SPDX + runtime security + container registry security + private registries + image lifecycle. (3) Serverless Security: Function as a Service (FaaS) security + AWS Lambda + Azure Functions + Google Cloud Functions + Knative + cold start security + IAM roles per function + function-to-function authentication + secrets management + dependency scanning + monitoring + observability. (4) Cloud Workload Protection Platform (CWPP): per Gartner CWPP definition + EDR for cloud workloads + behavioural analytics + machine learning + threat hunting + cloud-provider native threat detection services. (5) Image and Template Hardening: CIS Hardened Images + STIG Security Technical Implementation Guides + DISA Security Hardening Guides + golden images + immutable infrastructure + regular rebuild + vulnerability scanning + patch management per OS + per platform + JIS X 19790 hardening + JIS X 19592. (6) Cloud Configuration Management: Infrastructure as Code (IaC) + Terraform + AWS CloudFormation + Azure ARM/Bicep + GCP Deployment Manager + Pulumi + Crossplane + version controlled + reviewed + tested + drift detection + Cloud Security Posture Management (CSPM) + cloud-provider native configuration policy services + continuous compliance checks against CIS Benchmarks + ISMAP controls + automated remediation. (7) Multi-Tenancy Isolation: customer isolation + noisy neighbour protection + resource quotas + service-to-service isolation + dedicated vs shared resources + bare-metal vs virtual + customer-specific encryption keys. (8) Cloud Native Security: 12-Factor Apps + SaaS-specific controls + multi-region active-active + disaster recovery + Site Reliability Engineering (SRE). Coordinates with CIS Benchmarks + CIS Hardened Images + STIG + JIS X 19790 + JIS X 5051 + Kubernetes CIS Benchmark + Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) + Container Security Forum + CNCF Cloud Native Computing Foundation. ISMAP Cloud Infrastructure applies.
This control maps to 72 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.