Frameworks / NIST SP 800-145 / NISTSP145-8 NIST SP 800-145
Governance, Reporting, Education
NIST SP 800-145 NISTSP145-8: Governance, Reporting, and Stakeholder Education on Cloud Definition Establish governance that uses the NIST SP 800-145 definition as the canonical taxonomy in board reporting, regulator reporting, audit reporting, and stakeholder education. Cloud posture dashboards must aggregate the active service portfolio by service model and deployment model. Annual training for procurement officers, architects, risk owners, and audit staff must cover the five essential characteristics, three service models, and four deployment models. The CISO function must publish a quarterly cloud conformance report stating the count of services meeting all five characteristics, the count by service model, the count by deployment model, and any deviations or remediation in flight. Definition-update tracking must monitor NIST CSRC for revisions or replacement standards (such as ISO 17788 and ISO 22123 alignment) and update the canonical taxonomy accordingly.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 457 controls across 108 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-08 Cryptographic protection of data BSI-15 Security categorization BSI-17 Continuous monitoring strategy BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) ASD37-17 TLS encryption between email servers (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) ASD37-27 Outbound data loss prevention (Very Good) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) ISO27043-08 Information classification and labeling ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-24 Logging and monitoring ISO21434-08 Information classification and labeling ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-24 Logging and monitoring CH-FADP-13 Right to object and request blocking CH-FADP-16 Record keeping and accountability CH-FADP-17 Workplace and employment data CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-15 Data Breach Notification FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.3 Configuration Management AWWA-4.4 Audit Logging and Monitoring NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.PS-01 Configuration management practices are established and applied NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared API1164-02 Risk Management Framework API1164-13 Business Continuity and Recovery API1164-14 Physical Security API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface API1164-22 Configuration management for OT systems IEC62443-02 System security categorization IEC62443-13 Network security monitoring IEC62443-14 System security hardening IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents IEC62443-22 Configuration management for OT systems ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption ISO27019-02 System security categorization ISO27019-13 Network security monitoring ISO27019-14 System security hardening ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27019-22 Configuration management for OT systems IM8-CLD.2 Cloud Security Controls IM8-DAT.1 Data Classification IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal IM8-RES.3 Incident Response IM8-SEC.2 Access Control IM8-SEC.3 Network Security ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-SYS-01 System Hardening and Patch Management ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-03 Security Monitoring and Log Management ISMSP-SYS-05 Incident Response 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management 27011-8.4 Logging and monitoring 27011-8.6 Data protection and backup 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication 27400-6.4 Default Configuration Security 27400-6.5 Security monitoring and incident response 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures FFIEC-09 Encryption and key management FFIEC-10 Secure configuration standards FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement FEDRAMP-CM-1 Configuration Management Policy FEDRAMP-CM-2 Baseline Configuration FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) AT-DSG-7 Section 18 - Establishment of the Data Protection Authority CJIS-16 Cloud Computing CJIS-7 Configuration Management CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-2 Detective controls CAT-D3-3 Corrective controls CAT-D5-1 Incident planning and strategy CAT-IRP-4 Organizational characteristics FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 27010-10.1 Cryptographic Protection 27010-16.1 Continuity of Sharing 27010-8.2 Membership Termination 27010-9.2 Authentication of Sources 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) OWASPAPI-6 Security Misconfiguration and Secure API Design DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations APPI-A34 Request for Correction, Addition or Deletion APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information BB-DPA-1 Section 1 - Short Title BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-4 Section 4 - Principles Relating to Processing IS.AR.215 Information Security Incident Response IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.225 External Reporting UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-14 Cyber security event logging 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management ISO-22320-5.2 Incident management process ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples PAKPDPB-5 Security of Processing and Personal Data Breach Notification PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO CYB-2 Account Security Measures CYB-5 Cyber Incident Response Plan USMTSA-2 Cybersecurity Assessment and CSO Designation CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection CA-ITSG33-SC-01 Security Control Catalogue CA-ITSG33-SC-03 Cloud Security DIQ-1 Data Integration and Interoperability DSO-3 Data Access Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) CA-8 Penetration Testing IR-4 Incident Handling CA-8 Penetration Testing IR-4 Incident Handling IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-PS-01 Facility Security ISO20000-10 Configuration management ISO20000-11 Incident management 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team ITIL4-10 Configuration management ITIL4-11 Incident management BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections NZISM-3 Personnel Security, Physical Security, and Cryptography NZISM-5 Network Security, System Hardening, and Application Security NGOB-3 API Security Standards, mTLS, and Encryption NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN PSPF24-1 Security Culture, Governance, Risk Management PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight RUSPD-2 Lawful Basis, Consent, Notice RUSPD-4 Special Categories, Biometric Data PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data D.1 Incident Response Planning D.2 Incident Reporting CPSC-CS.2 Authentication and Access Controls CPSC-CS.3 Data Protection for Safety Systems VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AMLCTF-35 Identity Verification Standard CPS230-13 Board Accountability for Operational Risk Management AS9100D-8.1 Operational Planning and Control 4.4.7 Emergency and Incident Response AL-DPA-14 Direct Marketing CA-12 Deploys Through Policies and Procedures QMSR-820.45 Device labelling and packaging controls (§820.45) ICP-24 Macroprudential Surveillance and Insurance Supervision 60601-1.7.1 Equipment identification and marking ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO-19650-2-5.7 Information model delivery ISO-26000-6.7 Consumer issues ISO-26262-8-7 Configuration management ISO23894-A.5 Privacy and Data Protection in AI ISO-25012-4.11 Traceability 27006-9.4 Surveillance and recertification STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NFPA1600-6.3 Emergency Response Operations NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation EHDSREG-6 Phased Application and Enforcement SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration TEFCAREC-1 Common Agreement Conformance and Onboarding UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.) ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMCADIGITAL-2 Personal Information Protection and Consumer Protection VPSHR-3 Implementation Guidance and Reporting Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 457 it maps to, and the evidence behind each claim, over MCP and REST.