NIST SP 800-190
NIST SP 800-190: Cloud Operations & Monitoring

NIST SP 800-190 NIST190-21: Cloud security monitoring and logging

Cloud security monitoring and logging. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Operations & Monitoring.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 4 controls

  • BSI-17 Continuous monitoring strategy
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

NIST SP 800-53 Rev 5 · 4 controls

FedRAMP High · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling

FedRAMP Moderate · 2 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.3 Network Security

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • CA-ITSG33-SC-03 Cloud Security
  • DIQ-1 Data Integration and Interoperability
  • CJIS-16 Cloud Computing
  • CAT-D3-2 Detective controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • ICP-24 Macroprudential Surveillance and Insurance Supervision
  • 62351-14 Cyber security event logging

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO28001-PS-01 Facility Security
  • ISO-25012-4.11 Traceability
  • 27006-9.4 Surveillance and recertification

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27043:2015 · 1 control

  • ISO27043-24 Logging and monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/SAE 21434 · 1 control

  • ISO21434-24 Logging and monitoring
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

OpenSSF Scorecard · 1 control

  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • ISMSP-SYS-03 Security Monitoring and Log Management
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UK-TSA-MON-01 Security Monitoring
  • US-ITAR-EAR-DS-02 Cloud and Storage
  • US-SEC-DA-SC-03 ETF Framework

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 800-190: Cloud Operations & Monitoring

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.