Skip to content

Infrastructure Security

What is Infrastructure Security?

Security measures for protecting the core technology infrastructure including servers, networks, storage, and operating systems from threats.

Information Security

Each of these is named in at least one of the same controls as infrastructure security. The number is how many controls name both.

What the standards actually require on infrastructure security

Requirements naming infrastructure security across 6 standards, quoted from the control text.

NIST SP 800-1905 controls

Cloud workload protection. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.

NIST190-18 · Cloud workload protection

Align cybersecurity practices with NIST CSF and AWIA Section 2013 requirements for water infrastructure security.

AWWA-1.4 · Compliance and Regulatory Alignment
FISMA1 control

44 USC 3553 - Authority and Functions of the Director of OMB + the CISA Director. OMB DIRECTOR AUTHORITY: (a) overseeing agency information security policies + practices;

FISMA-3553-OMB-CISA-BOD · OMB and CISA Authority and Binding Operational Directives (44 USC 3553)

34 CFR 99.31(a)(6)(iii)(D) safeguards requirement + the PTAC Best Practices Guidance + SPPO Guidance. The 2011 final rule explicitly requires APPROPRIATE METHODS to PROTECT PII when disclosed under the studies + audit + evaluation exceptions.

FERPA-Safeguards-PTAC · Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;

HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

Questions people ask about infrastructure security

What is Infrastructure Security?
Security measures for protecting the core technology infrastructure including servers, networks, storage, and operating systems from threats.
Why is Infrastructure Security important for compliance?
Infrastructure Security is a key concept in Information Security. Understanding infrastructure security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Infrastructure Security?
Infrastructure Security appears in the requirement text of ITU-T X.805 - Security Architecture for End-to-End Communications, NIST SP 800-190, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), FISMA, Family Educational Rights and Privacy Act (FERPA). Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Infrastructure Security?
Explore our compliance framework pages to see how infrastructure security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Infrastructure Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.