NIST SP 800-146
Cloud Computing Synopsis and Recommendations
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Adoption Strategy
| Code | Title |
|---|---|
| SP800-146-1 | Cloud Adoption Recommendation Alignment |
| SP800-146-18 | Workload Suitability Assessment |
| SP800-146-19 | Decision Framework Documentation |
Auditing
| Code | Title |
|---|---|
| SP800-146-16 | Auditing and Accountability Recommendations |
Deployment Model Community
| Code | Title |
|---|---|
| SP800-146-7 | Community Cloud Recommendations |
Deployment Model Hybrid
| Code | Title |
|---|---|
| SP800-146-8 | Hybrid Cloud Recommendations |
Deployment Model Private
| Code | Title |
|---|---|
| SP800-146-6 | Private Cloud Recommendations |
Deployment Model Public
| Code | Title |
|---|---|
| SP800-146-5 | Public Cloud Recommendations |
Economics
| Code | Title |
|---|---|
| SP800-146-17 | Cost Management Recommendations |
Improvement
| Code | Title |
|---|---|
| SP800-146-20 | Lessons Learned Integration |
Interoperability
| Code | Title |
|---|---|
| SP800-146-12 | Interoperability Considerations |
NIST SP 800-146: Cloud Governance
Governance of cloud security (NIST SP 800-146)
| Code | Title |
|---|---|
| NIST146-01 | Shared responsibility model definition |
| NIST146-02 | Cloud security policy and strategy |
| NIST146-03 | Cloud risk assessment |
| NIST146-04 | Regulatory compliance for cloud services |
| NIST146-05 | Cloud security roles and responsibilities |
NIST SP 800-146: Cloud Infrastructure Security
Securing cloud infrastructure (NIST SP 800-146)
| Code | Title |
|---|---|
| NIST146-16 | Virtual network segmentation |
| NIST146-17 | Container and serverless security |
| NIST146-18 | Cloud workload protection |
| NIST146-19 | Image and template hardening |
| NIST146-20 | Cloud configuration management |
NIST SP 800-146: Cloud Operations & Monitoring
Operating and monitoring cloud securely (NIST SP 800-146)
| Code | Title |
|---|---|
| NIST146-21 | Cloud security monitoring and logging |
| NIST146-22 | Incident response in cloud |
| NIST146-23 | Cloud vulnerability management |
| NIST146-24 | Cloud change management |
| NIST146-25 | Service level agreement management |
NIST SP 800-146: Data Protection in Cloud
Protecting data in cloud services (NIST SP 800-146)
| Code | Title |
|---|---|
| NIST146-11 | Data classification for cloud |
| NIST146-12 | Encryption of cloud-stored data |
| NIST146-13 | Data residency and sovereignty |
| NIST146-14 | Data backup and recovery in cloud |
| NIST146-15 | Secure data deletion in cloud |
NIST SP 800-146: Identity & Access in Cloud
Identity management in cloud environments (NIST SP 800-146)
| Code | Title |
|---|---|
| NIST146-06 | Cloud identity management |
| NIST146-07 | Multi-factor authentication for cloud |
| NIST146-08 | Privileged access in cloud environments |
| NIST146-09 | Federation and single sign-on |
| NIST146-10 | API security and access tokens |
Open Issues
| Code | Title |
|---|---|
| SP800-146-9 | Security Open Issues Identification |
Performance
| Code | Title |
|---|---|
| SP800-146-10 | Performance Considerations |
Portability
| Code | Title |
|---|---|
| SP800-146-13 | Portability Considerations |
Privacy
| Code | Title |
|---|---|
| SP800-146-15 | Privacy Recommendations |
Reliability
| Code | Title |
|---|---|
| SP800-146-11 | Reliability and Availability Considerations |
Service Levels
| Code | Title |
|---|---|
| SP800-146-14 | Service Level Recommendations |
Service Model IaaS
| Code | Title |
|---|---|
| SP800-146-4 | IaaS Operational Recommendations |
Service Model PaaS
| Code | Title |
|---|---|
| SP800-146-3 | PaaS Operational Recommendations |
Service Model SaaS
| Code | Title |
|---|---|
| SP800-146-2 | SaaS Operational Recommendations |
Your Compliance Coverage
If you comply with NIST SP 800-146, you already cover:
C5 (Germany)
42%
19 controls mapped
Compare →MTCS (Singapore)
42%
19 controls mapped
Compare →ISO 27017
42%
19 controls mapped
Compare →+ 658 more: NIST SP 800-144 (42%), Azure Security Benchmark (42%)
See all 661 mapped frameworks ↓Maps to 661 other frameworks
Frequently Asked Questions
What is NIST SP 800-146?
NIST SP 800-146 is a compliance framework from United States with 23 domains and 45 controls. Cloud Computing Synopsis and Recommendations It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-146 have?
NIST SP 800-146 has 45 controls organised across 23 domains. The largest domains are NIST SP 800-146: Cloud Governance (5 controls), NIST SP 800-146: Cloud Infrastructure Security (5 controls), NIST SP 800-146: Cloud Operations & Monitoring (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-146 map to?
NIST SP 800-146 maps to 661 other compliance frameworks. The top mapping partners are C5 (Germany) (42% coverage), MTCS (Singapore) (42% coverage), ISO 27017 (42% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST SP 800-146 compliance?
Start your NIST SP 800-146 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-146 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required