Frameworks / NIST SP 800-190 / NIST190-01 NIST SP 800-190
NIST SP 800-190: Cloud Governance
NIST SP 800-190 NIST190-01: Shared responsibility model definition Shared responsibility model definition. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Governance.
What else in your programme already covers this This control maps to 247 controls across 120 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C RG5.71-C.3 Cyber Security Training RG5.71-C.5 Recovery and Restoration RG5.71-C.6 Configuration Management 1.2 Operating System Privileged Account Control 1.3 Virtualisation Platform Protection 3.3 Configure Data Access Control Lists DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 6.5 Preparing and Distributing Audit Report 6.7 Conducting Audit Follow-up STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner SOC2-CC7.4 Responds to identified security incidents through defined procedures C1 Organizational Boundary C3 Scope 1 and 2 Coverage 4.4.1 Resources, Roles, Responsibility, and Authority CPG-6.B Supply Chain Incident Reporting FFIEC-05 Roles and responsibilities definition CA-9 Internal System Connections CA-9 Internal System Connections ICP-1 Objectives, Powers and Responsibilities of the Supervisor 6.7 Conducting Audit Follow-up CA-9 Internal System Connections CA-9 Internal System Connections CA-9 Internal System Connections NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OSSFSC-1 Branch Protection, Code Review, and Repository Governance 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used, PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) RCEPEC-1 Online Personal Information Protection (12.13) SUPCHAIN-1 Build Integrity - Source, Build, Provenance SCA-S2 Interpretation and Definitions SWE-2 Relationship to GDPR FADP-5 Definitions (Article 5) UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11) SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Cloud Governance Query this from an agent The graph holds this control, the 247 it maps to, and the evidence behind each claim, over MCP and REST.