NIST SP 800-146
IaaS Operational Posture

NIST SP 800-146 NISTSP146-4: IaaS Operational Recommendations and Workload Hardening

Apply NIST SP 800-146 Chapter 7 IaaS operational recommendations to every IaaS service consumed. Coverage must include (a) infrastructure-as-code as the canonical provisioning method (no manual console provisioning of production), (b) base image and template hardening with documented baseline (CIS / DISA STIG / vendor secure baseline), (c) workload protection (host-based intrusion detection, anti-malware, file integrity monitoring), (d) network segmentation (VPC, subnet, security group, network ACL) with default-deny posture, (e) container and serverless protection where the workload is containerised or function-based, (f) configuration management and drift detection. Maintain an IaaS workload register that records operational posture and applies continuous compliance scanning.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 107 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

API 1164 · 4 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process

IEC 62443 · 4 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-13 Network security monitoring
  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • AWWA-3.1 Network Segmentation
  • AWWA-4.3 Configuration Management
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CA-ITSG33-SC-03 Cloud Security
  • CJIS-16 Cloud Computing
  • CJIS-7 Configuration Management
  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls
  • FFIEC-06 Network security and segmentation
  • FFIEC-10 Secure configuration standards

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • ISO-26262-8-7 Configuration management
  • ISO-26262-8-8 Change management

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-06 Change management processes
  • ISO20000-10 Configuration management

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation

ITIL 4 · 2 controls

  • ITIL4-06 Change management processes
  • ITIL4-10 Configuration management
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.3 Network Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-01 System Hardening and Patch Management
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • DIQ-1 Data Integration and Interoperability
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • ISO28001-PS-01 Facility Security

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27043:2015 · 1 control

  • ISO27043-27 Network security management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ISO/SAE 21434 · 1 control

  • ISO21434-27 Network security management
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 107 it maps to, and the evidence behind each claim, over MCP and REST.