8 results · ● Live web index
cloudaware.com article

NIST Cloud Security: Framework, Controls & Checklist 2026

https://cloudaware.com/blog/nist-cloud-security

NIST cloud security is not a single framework. It is a collection of publications from the National Institute of Standards and Technology that define security outcomes, control requirements, and audit expectations for information systems, including cloud environments. [...] There is no single NIST cloud security standard. The useful model is a stack of documents, each answering a different question. The core set is:nist cloud security nist cloud security But don’t treat any of them as “the standard,” or you will miss parts of the model: ## The NIST Cloud Security Framework explained The NIST Cloud Security Framework most teams refer to is CSF 2.0. It organizes security work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. [...] NIST CSF 2.0 defines security outcomes. It tells you what the program should achieve across Govern, Identify, Protect, Detect, Respond, and Recover. SP 800-53 defines specific controls such as AC-2, CM-6, AU-6, and CA-7. CSF is useful for structure and reporting. SP 800-53 is where implementation and audit evidence usually start. Which NIST publications are relevant for cloud security?

Visit
wiz.io article

Top Cloud Security Standards & Frameworks: ISO/IEC, NIST, CIS

https://www.wiz.io/academy/compliance/cloud-security-standards

Cloud security standards are structured guidelines and regulations crafted to secure cloud computing environments, developed by international standards bodies, governmental agencies, and industry leaders. These standards cover various facets of cloud security, including data protection, identity and access management, and regulatory compliance, providing organizations and cloud service providers (CSPs) with a framework to safeguard sensitive data and cloud infrastructures. [...] The ISO/IEC standards for cloud security provide a framework for securing cloud infrastructure and data through an information security management system (ISMS). These standards are especially valuable for organizations managing personally identifiable information (PII) and protected health information (PHI), as they help organizations meet regulatory requirements, avoid compliance risks, and safeguard data privacy. [...] The ISO/IEC 27000 series, which includes standards like 27001, 27002, 27017, and 27018, is fundamental to cloud security management: ISO/IEC 27001 and 27002 provide general best practices for information security, focusing on risk management, access control, and data privacy. These standards lay the foundation for implementing security controls across various environments, including the cloud.

Visit
getastra.com article

NIST Cloud Security: Standards, Best Practices & Benefits

https://www.getastra.com/blog/compliance/nist/nist-cloud-security

NIST SP 800 – 500 is a special publication document released by NIST that provides security controls for the successful implementation of cloud security measures based on the NIST cyber security framework. Relevant controls for organizations in the cloud include risk assessments, access control & configuration management. ### What are NIST’s five essential cloud computing characteristics? [...] NIST establishes cloud security standards, guidelines, and best practices to secure cloud environments and manage cybersecurity risks. NIST defines cloud security as practices to protect data and the applications and infrastructure hosted in the cloud environment. NIST standards concerning cloud security include: [...] The NIST (National Institute of Standards and Technology) Cyber Security Framework was introduced to help organizations manage and reduce cybersecurity risks. It does not provide specific security controls; however, they are done through special publications. It enables easy customization of cybersecurity practices based on individual company requirements.

Visit
aquasec.com article

7 Cloud Security Frameworks and How to Choose

https://www.aquasec.com/cloud-native-academy/cspm/cloud-security-frameworks

#### 2. NIST Cybersecurity Framework The NIST Cybersecurity Framework offers a flexible approach to managing cybersecurity risk in cloud environments. It is structured around five core functions: Identify, Protect, Detect, Respond, and Recover. This framework guides organizations through the process of implementing effective cybersecurity measures, addressing both technological and procedural aspects. A new version of the framework, NIST CSF 2.0, was released in February 2024. [...] NIST’s approach is adaptable, allowing organizations to tailor the framework to their specific needs and risk profiles. It supports continuous improvement, encouraging organizations to evolve their security practices as the threat landscape changes. NIST’s framework is highly regarded for its comprehensiveness and versatility. Useful resources NIST CSF 2.0 quick start guide Full NIST CSF 2.0 framework (32 pages) #### 3. Cloud Security Alliance (CSA) [...] # Cloud Security Frameworks The Cloud Native ExpertsJune 9, 2024 ## What Is a Cloud Security Framework? A cloud security framework is a set of guidelines, best practices, standards, and procedures for securing cloud-based environments. It provides a structured approach to managing and securing cloud services, including data protection, access control, and threat mitigation.

Visit
nist.gov official

NIST Cloud Computing Standards Roadmap

https://www.nist.gov/system/files/documents/itl/cloud/NIST_SP-500-291_Version…

in which most of JTC 1 standards projects are being developed. JTC 1 SC 27 (IT Security Techniques) is the one JTC 1 SC that is completely focused on cyber security standardization. There are currently three cloud security standards projects in SC27. NIST CLOUD COMPUTING STANDARDS ROADMAP 92 ISO/IEC 4th WD 27017, Information security management - Guidelines on information security controls for the use of cloud computing services based on ISO/IEC 27002 (Technical Specification) Provides [...] Table 10 – Security Standards: Security Controls NIST CLOUD COMPUTING STANDARDS ROADMAP 57 Categorization Available Standards SDO Status Security Policy Management ATIS-02000008 Trusted Information Exchange (TIE) ATIS Approved Standard Commercially Available FIPS 199 Standards for Security Categorization of Federal Information and Information Systems NIST Approved Standard Testing Market Acceptance FIPS 200 Minimum Security Requirements for Federal Information and Information Systems NIST [...] Standard Market Acceptance Table 9 – Security Standards: Security Monitoring & Incident Response NIST CLOUD COMPUTING STANDARDS ROADMAP 56 Categorization Available Standards SDO Status Security Controls Cloud Controls Matrix Version 1.3 CSA Approved Standard ISO/IEC 27001:2005 Information Technology – Security Techniques Information Security Management Systems Requirements ISO/IEC Approved Standard ISO/IEC WD TS 27017 Information technology -- Security techniques -- Information security

Visit
cloudsecurityalliance.org article

Introduction to the NIST Cybersecurity Framework | CSA

https://cloudsecurityalliance.org/blog/2021/04/21/introduction-to-the-nist-cy…

The NIST Cybersecurity Framework (NIST CSF) was created via a collaboration between the United States government and industry as a voluntary framework to promote the protection of critical infrastructure, and is based on existing standards, guidelines, and practices. The NIST CSF consists of three main components: Core, Implementation Tiers, and Profiles. In this blog, we will explore the Framework Core with the same example we used in Understanding CIS Controls and Benchmarks. [...] The Framework Core provides a “set of activities to achieve specific cybersecurity outcomes, and references examples of guidance to achieve those outcomes” and is separated into five high level Functions (Identify, Protect, Detect, Respond, Recover). Each function is further divided to 23 Categories (see figure below), each of which are assigned an identifier (ID) and are closely tied to needs and activities. The deepest level of abstraction in the NIST CSF are the supporting 108 Subcategories, [...] # Introduction to the NIST Cybersecurity Framework Published 04/21/2021 This blog was originally published by OpsCompass here Written by Kevin Hakanson, OpsCompass ### Security Framework Based on Standards, Guidelines, and Practices

Visit
ibm.com article

What is the NIST Cybersecurity Framework? | IBM

https://www.ibm.com/think/topics/nist

# What is the NIST Cybersecurity Framework? ## What is the NIST Cybersecurity Framework? The NIST Cybersecurity Framework (NIST CSF) provides comprehensive guidance and best practices that private sector organizations can follow to improve information security and cybersecurity risk management. The National Institute of Standards and Technology (NIST) is a non-regulatory agency that promotes innovation by advancing measurement science, standards and technology. [...] On 12 February 2013, Executive Order (EO) 13636 "Improving Critical Infrastructure Cybersecurity" was issued. This began NIST’s work with the US private sector to "identify existing voluntary consensus standards and industry best practices to build them into a Cybersecurity Framework." The result of this collaboration was the NIST Cybersecurity Framework Version 1.0. [...] The Cybersecurity Enhancement Act (CEA) of 2014 broadened NIST's efforts in developing the Cybersecurity Framework. Today, the NIST CSF is still one of the most widely adopted security frameworks across all US industries. ## NIST Cybersecurity Framework core structure NIST Cybersecurity Framework includes functions, categories, subcategories and informative references.

Visit
csrc.nist.gov official

NIST Publishes SP 800-210: AC Guidance for Cloud | CSRC

https://csrc.nist.gov/news/2020/nist-publishes-sp-800-210-ac-guidance-for-cloud

NIST has published Special Publication (SP) 800-210, General Access Control Guidance for Cloud Systems, which presents an initial step toward understanding security challenges in cloud systems by analyzing the access control (AC) considerations in all three cloud service delivery models—Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Essential characteristics that would affect the Cloud's AC design are also summarized, such as broad network [...] #### Related Topics Security and Privacy: access control, security controls, system authorization, systems security engineering Technologies: cloud & virtualization, servers Laws and Regulations: Federal Information Security Modernization Act National Institute of Standards and Technology logo Want updates about CSRC and our publications? Subscribe National Institute of Standards and Technology logo Contact Us | Our Other Offices [...] ) or means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. National Institute of Standards and Technology Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SPs) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Security & Privacy Applications Technologies Sectors

Visit