Skip to content

Evidence request lists

NIST SP 800-144

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Architecture and Isolation

NISTSP144-2
Cloud Architecture, Service Selection, and Tenant Isolation

Apply Section 5 cloud architecture and service selection covering IaaS + PaaS + SaaS + FaaS + serverless models + deployment models (public + private + community + hybrid + multicloud) per NIST SP 800-145. Assess tenant isolation (hypervisor + container + namespace + network + storage + memory + cache) per Section 5.4 including side-channel attacks (Spectre + Meltdown + Foreshadow + Zombieload + MDS + Microarchitectural Data Sampling) + noisy neighbour + microcode patches + hardware attestation. Apply Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) for shared responsibility.

Artefacts an auditor will ask for
  • Cloud architecture diagram
  • Service model selection rationale
  • Tenant isolation analysis
  • CSA CCM mapping
  • Hardware attestation
Where this commonly fails
  • Inappropriate service model
  • No isolation analysis
  • Missing CCM
  • No attestation

Availability and Resilience

NISTSP144-6
Availability, Resilience, BCP/DR, and SLA Management

Apply Section 7.4 availability and resilience planning including: cloud availability SLA assessment (99.95% + 99.99% + 99.999%) + outage credits + service-level objectives (SLOs) + Service Level Indicators (SLIs) + multi-AZ + multi-region + multi-cloud + active-active + active-passive architectures. Develop BCP/DR per cloud-native disaster recovery (Pilot Light + Warm Standby + Hot Standby + Active-Active multi-region) + RTO/RPO targets + chaos engineering (Chaos Monkey + Gremlin + AWS Fault Injection Service + Azure Chaos Studio) + game days. Manage SLA per Section 7.20 including monitoring + reporting + escalation + outage credits + customer compensation.

Artefacts an auditor will ask for
  • Availability architecture
  • BCP/DR strategy
  • Chaos engineering
  • SLA dashboard
  • Outage credits
Where this commonly fails
  • Single AZ
  • No multi-region
  • No chaos engineering
  • No SLA monitoring

Data Protection

NISTSP144-3
Data Classification, Handling, and Sovereignty

Apply Section 6 data classification and handling in cloud per FIPS 199 categorisation + agency data sensitivity + GDPR + CCPA + 24 state privacy laws + HIPAA + PCI DSS + SOX. Address data residency and sovereignty per Section 6.2 covering: in-country data localisation requirements (EU + China + Russia + UAE + Saudi + India + Brazil) + cross-border transfer mechanisms (SCCs + BCRs + Data Privacy Framework) + government access (CLOUD Act + Schrems II) + data flow mapping + processing location attestation. Configure secure data deletion in cloud per Section 6.3 including: crypto-shredding + sanitisation + verification + provider attestation.

Artefacts an auditor will ask for
  • Data classification scheme
  • FIPS 199 categorisation
  • Data residency mapping
  • Sovereignty analysis
  • Secure deletion procedures
Where this commonly fails
  • No classification
  • Sovereignty unclear
  • Improper deletion
  • No attestation

Encryption and Keys

NISTSP144-4
Encryption, Key Management, and BYOK

Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (confidential computing + Intel SGX + AMD SEV + AWS Nitro Enclaves + Azure Confidential Computing + Google Confidential VMs) + key management services (AWS KMS + Azure Key Vault + Google Cloud KMS + HashiCorp Vault) + HSM (CloudHSM + Dedicated HSM + Bring Your Own HSM) + PQC migration per FIPS 203/204/205 + envelope encryption + key rotation.

Artefacts an auditor will ask for
  • Encryption strategy
  • BYOK/HYOK implementation
  • KMS configuration
  • HSM deployment
  • Confidential computing
  • PQC migration plan
Where this commonly fails
  • Provider keys only
  • No BYOK
  • No HSM
  • No PQC plan

Governance and Trust

NISTSP144-1
Cloud Governance, Risk Assessment, and Provider Trust Evaluation

Apply NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing published December 2011 + companion to NIST SP 800-145 + NIST SP 800-146 + FedRAMP + DoD Cloud Security Requirements Guide. Establish cloud governance framework + cloud risk assessment per Section 4 covering shared responsibility model + provider trust evaluation (SOC 2 Type II + ISO 27001/27017/27018 + FedRAMP Authorization + DoD IL2-6 + CCM + STAR + customer due diligence). Coordinate with CIO + CISO + CDO + CFO + General Counsel.

Artefacts an auditor will ask for
  • Cloud governance framework
  • Cloud risk assessment
  • Provider due diligence
  • FedRAMP Authorization Boundary
  • SOC 2 Type II + ISO certifications
Where this commonly fails
  • No governance
  • No risk assessment
  • Missing due diligence
  • No FedRAMP Boundary

Identity and Access

NISTSP144-5
Identity and Access in Cloud, Federation, and Privileged Access

Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign-On (SSO) + risk-based authentication. Implement privileged access (PAM + JIT access + bastion hosts + session recording + just-enough-access JEA) + secrets management (Vault + Secrets Manager + Key Vault) + service accounts + managed identities + RBAC + ABAC + policy-as-code (OPA + Sentinel + Cloud Custodian).

Artefacts an auditor will ask for
  • Federation deployment
  • MFA enforcement
  • PAM with session recording
  • Policy-as-code (OPA)
  • Secrets management
Where this commonly fails
  • No federation
  • Weak MFA
  • No PAM
  • No policy-as-code

Monitoring and IR

NISTSP144-8
Monitoring, Incident Response, Exit Strategy, and Compliance

Apply Section 7.6 cloud security monitoring and logging via cloud-native services (CloudTrail + GuardDuty + Security Hub + Azure Monitor + Sentinel + Google Cloud Logging + Security Command Center) + SIEM/SOAR integration + 24/7 SOC. Implement incident response in cloud per Section 8.10 including provider coordination + customer responsibilities + forensic readiness + chain of custody + cloud-specific IR playbooks. Develop portability and interoperability + cloud exit strategy per Section 7.16 including data egress + format conversion + dependency mapping + alternative provider selection + crypto-shredding on exit. Address Section 7.11 privacy + Section 7.12 compliance mapping + Section 7.14 supply chain + Section 7.17 personnel security + Section 7.19 continuous monitoring of cloud services.

Artefacts an auditor will ask for
  • Cloud monitoring deployment
  • IR playbooks
  • Exit strategy
  • Compliance cross-walks
  • Continuous monitoring
Where this commonly fails
  • No cloud monitoring
  • No exit strategy
  • Missing compliance
  • No continuous monitoring

Workload and Configuration

NISTSP144-7
Cloud Workload Protection, Containers, Serverless, and Configuration

Apply Section 7.5 cloud workload protection covering CWPP (Cloud Workload Protection Platform - CrowdStrike Falcon + Trend Micro Deep Security + Wiz + Lacework + Orca Security + Aqua + Sysdig + Prisma Cloud) + image and template hardening (Packer + Hashicorp + AMI/VHD hardening + scanning) + container security (Docker + Kubernetes + Aqua + Twistlock + Anchore + Trivy + Falco) + serverless security (Lambda + Cloud Functions + Azure Functions + Vercel + Cloudflare Workers + IAM least privilege + cold-start security). Apply Section 7.18 cloud configuration management + CSPM (Cloud Security Posture Management - Wiz + Lacework + Prisma Cloud + Microsoft Defender for Cloud + AWS Security Hub + Azure Security Center) + IaC scanning (Checkov + tfsec + Snyk IaC + Bridgecrew).

Artefacts an auditor will ask for
  • CWPP deployment
  • Container security
  • Serverless security
  • CSPM tool
  • IaC scanning
Where this commonly fails
  • No CWPP
  • Insecure containers
  • No CSPM
  • No IaC scanning
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-144 framework page.