Frameworks / NIST SP 800-190 / 20 NIST SP 800-190
NIST SP 800-190: Cloud Infrastructure Security
NIST SP 800-190 20: Cloud configuration management Cloud configuration management. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.
What else in your programme already covers this This control maps to 72 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection Clause 10 Change and configuration management SUP.8 Configuration Management CJIS-7 Configuration Management NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PSDTWO-2 SCA Exemptions and Risk-Based Authentication CISABD-1 Take Ownership of Customer Security Outcomes Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Cloud Infrastructure Security Query this from an agent The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.