Frameworks / NIST SP 800-190 / NIST190-08 NIST SP 800-190
NIST SP 800-190: Identity & Access in Cloud
NIST SP 800-190 NIST190-08: Privileged access in cloud environments Privileged access in cloud environments. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Identity & Access in Cloud.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 72 controls across 46 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements BSI-02 Access enforcement and least privilege DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO27799-01 ePHI access controls and authorization 27011-8.1 User Endpoint Devices ISO27043-14 Privileged access management 27400-6.1 Secure Device Design ISO21434-14 Privileged access management NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PTESPHASE-2 Intelligence Gathering (OSINT) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-01 Access Control Policy TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization UGA-10 Sensitive Personal Data Prohibition Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Identity & Access in Cloud Query this from an agent The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.