NIST SP 800-145
Governance, Reporting, Education

NIST SP 800-145 NISTSP145-8: Governance, Reporting, and Stakeholder Education on Cloud Definition

Establish governance that uses the NIST SP 800-145 definition as the canonical taxonomy in board reporting, regulator reporting, audit reporting, and stakeholder education. Cloud posture dashboards must aggregate the active service portfolio by service model and deployment model. Annual training for procurement officers, architects, risk owners, and audit staff must cover the five essential characteristics, three service models, and four deployment models. The CISO function must publish a quarterly cloud conformance report stating the count of services meeting all five characteristics, the count by service model, the count by deployment model, and any deviations or remediation in flight. Definition-update tracking must monitor NIST CSRC for revisions or replacement standards (such as ISO 17788 and ISO 22123 alignment) and update the canonical taxonomy accordingly.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 457 controls across 108 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 15 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-08 Cryptographic protection of data
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ASD37-33 Capture network traffic (Limited)

ISO/IEC 27043:2015 · 9 controls

  • ISO27043-08 Information classification and labeling
  • ISO27043-12 User access management and provisioning
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 9 controls

  • ISO21434-08 Information classification and labeling
  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-24 Logging and monitoring
  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-16 Record keeping and accountability
  • CH-FADP-17 Workplace and employment data
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-15 Data Breach Notification
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.3 Account Management
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.3 Configuration Management
  • AWWA-4.4 Audit Logging and Monitoring
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

API 1164 · 7 controls

  • API1164-02 Risk Management Framework
  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-22 Configuration management for OT systems

IEC 62443 · 7 controls

  • IEC62443-02 System security categorization
  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-22 Configuration management for OT systems

ISO 27799:2025 · 7 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27019:2024 · 7 controls

  • ISO27019-02 System security categorization
  • ISO27019-13 Network security monitoring
  • ISO27019-14 System security hardening
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • ISO27019-22 Configuration management for OT systems
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.1 Data Classification
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-RES.3 Incident Response
  • IM8-SEC.2 Access Control
  • IM8-SEC.3 Network Security

South Korea ISMS-P · 7 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-05 Incident Response

ISO/IEC 27011:2024 · 6 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management
  • 27011-8.4 Logging and monitoring
  • 27011-8.6 Data protection and backup

ISO/IEC 27400:2022 · 6 controls

  • 27400-6.1 Secure Device Design
  • 27400-6.2 Device Identity and Authentication
  • 27400-6.4 Default Configuration Security
  • 27400-6.5 Security monitoring and incident response
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion

OWASP ASVS · 6 controls

OWASP Top 10:2025 · 6 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

Bahrain PDPL · 5 controls

  • FFIEC-09 Encryption and key management
  • FFIEC-10 Secure configuration standards
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

FedRAMP Rev 5 · 5 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

OWASP MASVS · 5 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • CJIS-16 Cloud Computing
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • CAT-D3-2 Detective controls
  • CAT-D3-3 Corrective controls
  • CAT-D5-1 Incident planning and strategy
  • CAT-IRP-4 Organizational characteristics
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27010:2015 · 4 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-16.1 Continuity of Sharing
  • 27010-8.2 Membership Termination
  • 27010-9.2 Authentication of Sources
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

APPI · 3 controls

  • APPI-A34 Request for Correction, Addition or Deletion
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

GDPR · 3 controls

  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

ISO 22320:2018 · 3 controls

  • ISO-22320-5.2 Incident management process
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • CYB-2 Account Security Measures
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CA-ITSG33-SC-03 Cloud Security
  • DIQ-1 Data Integration and Interoperability
  • DSO-3 Data Access Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))

FedRAMP High · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling

FedRAMP Moderate · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PS-01 Facility Security

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-10 Configuration management
  • ISO20000-11 Incident management

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

ITIL 4 · 2 controls

  • ITIL4-10 Configuration management
  • ITIL4-11 Incident management
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • RUSPD-2 Lawful Basis, Consent, Notice
  • RUSPD-4 Special Categories, Biometric Data

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CPSC-CS.2 Authentication and Access Controls
  • CPSC-CS.3 Data Protection for Safety Systems
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AMLCTF-35 Identity Verification Standard
  • CPS230-13 Board Accountability for Operational Risk Management
  • AS9100D-8.1 Operational Planning and Control
  • 4.4.7 Emergency and Incident Response
  • AL-DPA-14 Direct Marketing
  • CA-12 Deploys Through Policies and Procedures
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

FIDO2 / WebAuthn · 1 control

  • ICP-24 Macroprudential Surveillance and Insurance Supervision
  • 60601-1.7.1 Equipment identification and marking
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO-26262-8-7 Configuration management

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-4.11 Traceability
  • 27006-9.4 Surveillance and recertification
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NFPA1600-6.3 Emergency Response Operations
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • EHDSREG-6 Phased Application and Enforcement

SWIFT CSCF · 1 control

  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)
  • ACE-CR-4 Cargo Release Authorization
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 457 it maps to, and the evidence behind each claim, over MCP and REST.