Frameworks / NIST SP 800-190 / 21 NIST SP 800-190
NIST SP 800-190: Cloud Operations & Monitoring
NIST SP 800-190 21: Cloud security monitoring and logging Cloud security monitoring and logging. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Operations & Monitoring.
What else in your programme already covers this This control maps to 123 controls across 67 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-17 Continuous monitoring strategy BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention CA-8 Penetration Testing IR-4 Incident Handling CA-8 Penetration Testing IR-4 Incident Handling 3.12 Segment Data Processing and Storage Based on Sensitivity 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process CA-8 Penetration Testing IR-4 Incident Handling NZISM-3 Personnel Security, Physical Security, and Cryptography NZISM-5 Network Security, System Hardening, and Application Security AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) DIQ-1 Data Integration and Interoperability FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) ICP-24 Macroprudential Surveillance and Insurance Supervision 27400-6.5 Security monitoring and incident response NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes TSAPIPE-2 OT/IT Network Segmentation and Access Control Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Cloud Operations & Monitoring Query this from an agent The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.