Apply NIST SP 800-146 Section 9.4 (Security Recommendations) and Section 9.5 (Privacy Recommendations) across the cloud portfolio. Security recommendations must address (a) shared responsibility model documented per service-model, (b) identity and access management (federation, MFA, privileged access, JIT access), (c) data protection (classification, encryption at rest and in transit, key management with consumer-controlled keys where appropriate, secure deletion), (d) network protection (segmentation, default deny, edge protection), (e) monitoring and logging (cloud audit trail, SIEM ingestion, retention), (f) incident response (cloud-aware IR runbooks, provider notification channel, evidence collection capability), (g) vulnerability management (continuous scanning, patch responsibility split). Privacy recommendations must address data subject rights, lawful basis for processing in the chosen jurisdiction, cross-border transfer mechanism, and provider sub-processor inventory. Address Section 9.6 Open Security Issues explicitly (multi-tenancy data leakage, VM escape, side-channel, provider insider threat) in the cloud risk register.
This control maps to 459 controls across 109 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 459 it maps to, and the evidence behind each claim, over MCP and REST.