Frameworks / NIST SP 800-190 / NIST190-08 NIST SP 800-190
NIST SP 800-190: Identity & Access in Cloud
NIST SP 800-190 NIST190-08: Privileged access in cloud environments Privileged access in cloud environments. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Identity & Access in Cloud.
What else in your programme already covers this This control maps to 78 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) SOC2-CC6.2 Prior to granting access, registration and authorization processes are established SOC2-CC6.3 Role-based access and least privilege are enforced SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements BSI-02 Access enforcement and least privilege DSO-3 Data Access Management 62351-8 Role-based access control (RBAC) NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification TSAPIPE-2 OT/IT Network Segmentation and Access Control UGA-10 Sensitive Personal Data Prohibition Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Identity & Access in Cloud Query this from an agent The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.