Infrastructure Security
What is Infrastructure Security?
Security measures for protecting the core technology infrastructure including servers, networks, storage, and operating systems from threats.
Terms that appear alongside infrastructure security
Each of these is named in at least one of the same controls as infrastructure security. The number is how many controls name both.
- cloud infrastructure security 25 shared controls
- nist 9 shared controls
- iso 27017 5 shared controls
- network segmentation 5 shared controls
- serverless security 5 shared controls
- cloud workload protection 5 shared controls
- hardening 5 shared controls
- cloud configuration management 5 shared controls
Frameworks that govern infrastructure security
What the standards actually require on infrastructure security
Requirements naming infrastructure security across 6 standards, quoted from the control text.
Security Layer 1 Infrastructure per X.805 Clause 7.1: The Infrastructure Security Layer consists of network facilities (transmission facilities and network elements) protected by the security measures.
X805-Layer1-Infrastructure-Security-Transmission-Facilities-Network-Elements-Lines-Routers-Switches · ITU-T X.805 Security Layer 1 - Infrastructure Security + Transmission Facilities + Network Elements + Routers + Switches + Lines + Physical + Datacenter + Optical + Radio Access + Wireless + Wireline + Edge →Cloud workload protection. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.
NIST190-18 · Cloud workload protection →Align cybersecurity practices with NIST CSF and AWIA Section 2013 requirements for water infrastructure security.
AWWA-1.4 · Compliance and Regulatory Alignment →44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices;
FISMA-3553-OMB-CISA-BOD · OMB and CISA Authority and Binding Operational Directives (44 USC 3553) →34 CFR 99.31(a)(6)(iii)(D) safeguards requirement + the PTAC Best Practices Guidance + SPPO Guidance. The 2011 final rule explicitly requires APPROPRIATE METHODS to PROTECT PII when disclosed under the studies + audit + evaluation exceptions.
FERPA-Safeguards-PTAC · Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) →HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;
HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel →Questions people ask about infrastructure security
What is Infrastructure Security?
Why is Infrastructure Security important for compliance?
Which compliance frameworks address Infrastructure Security?
Where can I learn more about Infrastructure Security?
See how Infrastructure Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.