NIST SP 800-190
NIST SP 800-190: Cloud Operations & Monitoring

NIST SP 800-190 NIST190-23: Cloud vulnerability management

Cloud vulnerability management. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Operations & Monitoring.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-07 Dependency Management and SBOM

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

NIST SP 800-53 Rev 5 · 2 controls

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CPG-5.A Vulnerability Disclosure Program
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture

OWASP SAMM · 1 control

  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SOCI-S30CU Vulnerability assessments
  • SCA-S26 Licensing Framework
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • UKOPRES-4 Incident Management, Lessons Learned, Comms

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 800-190: Cloud Operations & Monitoring

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.