NIST SP 800-144
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Architecture and Isolation
Apply Section 5 cloud architecture and service selection covering IaaS + PaaS + SaaS + FaaS + serverless models + deployment models (public + private + community + hybrid + multicloud) per NIST SP 800-145. Assess tenant isolation (hypervisor + container + namespace + network + storage + memory + cache) per Section 5.4 including side-channel attacks (Spectre + Meltdown + Foreshadow + Zombieload + MDS + Microarchitectural Data Sampling) + noisy neighbour + microcode patches + hardware attestation. Apply Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) for shared responsibility.
- Cloud architecture diagram
- Service model selection rationale
- Tenant isolation analysis
- CSA CCM mapping
- Hardware attestation
- Inappropriate service model
- No isolation analysis
- Missing CCM
- No attestation
Availability and Resilience
Apply Section 7.4 availability and resilience planning including: cloud availability SLA assessment (99.95% + 99.99% + 99.999%) + outage credits + service-level objectives (SLOs) + Service Level Indicators (SLIs) + multi-AZ + multi-region + multi-cloud + active-active + active-passive architectures. Develop BCP/DR per cloud-native disaster recovery (Pilot Light + Warm Standby + Hot Standby + Active-Active multi-region) + RTO/RPO targets + chaos engineering (Chaos Monkey + Gremlin + AWS Fault Injection Service + Azure Chaos Studio) + game days. Manage SLA per Section 7.20 including monitoring + reporting + escalation + outage credits + customer compensation.
- Availability architecture
- BCP/DR strategy
- Chaos engineering
- SLA dashboard
- Outage credits
- Single AZ
- No multi-region
- No chaos engineering
- No SLA monitoring
Data Protection
Apply Section 6 data classification and handling in cloud per FIPS 199 categorisation + agency data sensitivity + GDPR + CCPA + 24 state privacy laws + HIPAA + PCI DSS + SOX. Address data residency and sovereignty per Section 6.2 covering: in-country data localisation requirements (EU + China + Russia + UAE + Saudi + India + Brazil) + cross-border transfer mechanisms (SCCs + BCRs + Data Privacy Framework) + government access (CLOUD Act + Schrems II) + data flow mapping + processing location attestation. Configure secure data deletion in cloud per Section 6.3 including: crypto-shredding + sanitisation + verification + provider attestation.
- Data classification scheme
- FIPS 199 categorisation
- Data residency mapping
- Sovereignty analysis
- Secure deletion procedures
- No classification
- Sovereignty unclear
- Improper deletion
- No attestation
Encryption and Keys
Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (confidential computing + Intel SGX + AMD SEV + AWS Nitro Enclaves + Azure Confidential Computing + Google Confidential VMs) + key management services (AWS KMS + Azure Key Vault + Google Cloud KMS + HashiCorp Vault) + HSM (CloudHSM + Dedicated HSM + Bring Your Own HSM) + PQC migration per FIPS 203/204/205 + envelope encryption + key rotation.
- Encryption strategy
- BYOK/HYOK implementation
- KMS configuration
- HSM deployment
- Confidential computing
- PQC migration plan
- Provider keys only
- No BYOK
- No HSM
- No PQC plan
Governance and Trust
Apply NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing published December 2011 + companion to NIST SP 800-145 + NIST SP 800-146 + FedRAMP + DoD Cloud Security Requirements Guide. Establish cloud governance framework + cloud risk assessment per Section 4 covering shared responsibility model + provider trust evaluation (SOC 2 Type II + ISO 27001/27017/27018 + FedRAMP Authorization + DoD IL2-6 + CCM + STAR + customer due diligence). Coordinate with CIO + CISO + CDO + CFO + General Counsel.
- Cloud governance framework
- Cloud risk assessment
- Provider due diligence
- FedRAMP Authorization Boundary
- SOC 2 Type II + ISO certifications
- No governance
- No risk assessment
- Missing due diligence
- No FedRAMP Boundary
Identity and Access
Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign-On (SSO) + risk-based authentication. Implement privileged access (PAM + JIT access + bastion hosts + session recording + just-enough-access JEA) + secrets management (Vault + Secrets Manager + Key Vault) + service accounts + managed identities + RBAC + ABAC + policy-as-code (OPA + Sentinel + Cloud Custodian).
- Federation deployment
- MFA enforcement
- PAM with session recording
- Policy-as-code (OPA)
- Secrets management
- No federation
- Weak MFA
- No PAM
- No policy-as-code
Monitoring and IR
Apply Section 7.6 cloud security monitoring and logging via cloud-native services (CloudTrail + GuardDuty + Security Hub + Azure Monitor + Sentinel + Google Cloud Logging + Security Command Center) + SIEM/SOAR integration + 24/7 SOC. Implement incident response in cloud per Section 8.10 including provider coordination + customer responsibilities + forensic readiness + chain of custody + cloud-specific IR playbooks. Develop portability and interoperability + cloud exit strategy per Section 7.16 including data egress + format conversion + dependency mapping + alternative provider selection + crypto-shredding on exit. Address Section 7.11 privacy + Section 7.12 compliance mapping + Section 7.14 supply chain + Section 7.17 personnel security + Section 7.19 continuous monitoring of cloud services.
- Cloud monitoring deployment
- IR playbooks
- Exit strategy
- Compliance cross-walks
- Continuous monitoring
- No cloud monitoring
- No exit strategy
- Missing compliance
- No continuous monitoring
Workload and Configuration
Apply Section 7.5 cloud workload protection covering CWPP (Cloud Workload Protection Platform - CrowdStrike Falcon + Trend Micro Deep Security + Wiz + Lacework + Orca Security + Aqua + Sysdig + Prisma Cloud) + image and template hardening (Packer + Hashicorp + AMI/VHD hardening + scanning) + container security (Docker + Kubernetes + Aqua + Twistlock + Anchore + Trivy + Falco) + serverless security (Lambda + Cloud Functions + Azure Functions + Vercel + Cloudflare Workers + IAM least privilege + cold-start security). Apply Section 7.18 cloud configuration management + CSPM (Cloud Security Posture Management - Wiz + Lacework + Prisma Cloud + Microsoft Defender for Cloud + AWS Security Hub + Azure Security Center) + IaC scanning (Checkov + tfsec + Snyk IaC + Bridgecrew).
- CWPP deployment
- Container security
- Serverless security
- CSPM tool
- IaC scanning
- No CWPP
- Insecure containers
- No CSPM
- No IaC scanning
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-144 framework page.