NIST SP 800-146
IaaS Operational Posture

NIST SP 800-146 4: IaaS Operational Recommendations and Workload Hardening

Apply NIST SP 800-146 Chapter 7 IaaS operational recommendations to every IaaS service consumed. Coverage must include (a) infrastructure-as-code as the canonical provisioning method (no manual console provisioning of production), (b) base image and template hardening with documented baseline (CIS / DISA STIG / vendor secure baseline), (c) workload protection (host-based intrusion detection, anti-malware, file integrity monitoring), (d) network segmentation (VPC, subnet, security group, network ACL) with default-deny posture, (e) container and serverless protection where the workload is containerised or function-based, (f) configuration management and drift detection. Maintain an IaaS workload register that records operational posture and applies continuous compliance scanning.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.