NIST 800-53: Cloud Security Controls
Azure 50 automated checks
Security and privacy controls mapped to NIST SP 800-53 Rev. 5 for cloud resources
Access Control (AC)
- Storage account must disable anonymous blob public access
- Key Vault should use RBAC authorization
- Container Registry must disable admin user
- Organization should perform periodic access reviews
- Organization should establish access control policies (AC-1)
- Organization should manage information system accounts (AC-2)
- Organization should enforce separation of duties (AC-5)
Audit and Accountability (AU)
Awareness & Training (AT)
Awareness and Training (AT)
Configuration Management (CM)
Contingency Planning (CP)
Identification & Authentication (IA)
Incident Response (IR)
Planning (PL)
Program Management (PM)
Risk Assessment (RA)
Security Assessment (CA)
System & Communications Protection (SC)
- Storage account must enforce HTTPS transfer
- Storage account must use TLS 1.2 minimum
- Storage account must deny public network access by default
- Key Vault should disable public network access
- SQL Server should disable public network access
- SQL Server must use TLS 1.2 or higher
- Virtual Machine must enable encryption at host
- Container Registry should restrict public network access
- App Service must enforce HTTPS only
- App Service must use TLS 1.2 or higher
- App Service must disable FTP or require FTPS only
- Redis Cache must disable non-SSL port
System & Information Integrity (SI)
System and Services Acquisition (SA)
Measure your NIST 800-53: Cloud Security Controls posture
CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.