NIST SP 800-146 NISTSP146-4: IaaS Operational Recommendations and Workload Hardening
Apply NIST SP 800-146 Chapter 7 IaaS operational recommendations to every IaaS service consumed. Coverage must include (a) infrastructure-as-code as the canonical provisioning method (no manual console provisioning of production), (b) base image and template hardening with documented baseline (CIS / DISA STIG / vendor secure baseline), (c) workload protection (host-based intrusion detection, anti-malware, file integrity monitoring), (d) network segmentation (VPC, subnet, security group, network ACL) with default-deny posture, (e) container and serverless protection where the workload is containerised or function-based, (f) configuration management and drift detection. Maintain an IaaS workload register that records operational posture and applies continuous compliance scanning.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 107 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.