NIST SP 800-144
Monitoring and IR

NIST SP 800-144 8: Monitoring, Incident Response, Exit Strategy, and Compliance

Apply Section 7.6 cloud security monitoring and logging via cloud-native services (CloudTrail + GuardDuty + Security Hub + Azure Monitor + Sentinel + Google Cloud Logging + Security Command Center) + SIEM/SOAR integration + 24/7 SOC. Implement incident response in cloud per Section 8.10 including provider coordination + customer responsibilities + forensic readiness + chain of custody + cloud-specific IR playbooks. Develop portability and interoperability + cloud exit strategy per Section 7.16 including data egress + format conversion + dependency mapping + alternative provider selection + crypto-shredding on exit. Address Section 7.11 privacy + Section 7.12 compliance mapping + Section 7.14 supply chain + Section 7.17 personnel security + Section 7.19 continuous monitoring of cloud services.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.