Skip to main content

Cloud Native Security Controls (CNSC) to NIST SP 800-53 Rev. 5 Mapping

This document maps the Cloud Native Security Controls Catalog to NIST 800-53 SP Rev.5 Guidelines.

NIST SP 800-53 crosswalk

CNSC guidelineRelationshipNIST control(s)Notes
CNSC-1relates-toIA-5(7)Runtime Secret Injection (CNSC-1) · NIST IA-5(7) — Runtime injection prevents static authenticators from being embedded in application code or container images
CNSC-2relates-toIA-9Mutual Authentication (CNSC-2) · NIST IA-9 — Mutual authentication between workloads establishes bidirectional identity verification before service communication
CNSC-3relates-toSC-12Cryptographic Key Management (CNSC-3) · NIST SC-12 — Key rotation is a key management lifecycle activity addressed by SC-12
CNSC-4relates-toSC-12Cryptographic Key Lifecycle Management (CNSC-4) · NIST SC-12 — Short key lifespan is a key management lifecycle policy addressed by SC-12
CNSC-5relates-toSA-9
SC-12
Sensitive Credential Management (CNSC-5) · NIST SA-9 — Independent credential management addresses risk from reliance on external cloud provider services
Sensitive Credential Management (CNSC-5) · NIST SC-12 — Generation and management of credentials is a key management lifecycle activity
CNSC-6relates-toIA-13
AC-3
Identification and Authentication (CNSC-6) · NIST IA-13 — Independent authentication and authorization map to the separation of identity providers from authorization servers
Identification and Authentication (CNSC-6) · NIST AC-3 — Authorization decisions are enforced as a distinct process from identity authentication
CNSC-7relates-toAC-3Authentication and Authorization Enforcement (CNSC-7) · NIST AC-3 — Independent enforcement of authorization is distinct from the authentication mechanism that establishes identity
CNSC-8relates-toSI-4(2)Continuous System Monitoring (CNSC-8) · NIST SI-4(2) — Real-time access control and permission updates require automated monitoring to detect and respond to changes
CNSC-9relates-toAC-3(13)
AC-3(7)
Privileged-based Authorization (CNSC-9) · NIST AC-3(13) — Workload authorization based on pre-assigned attributes aligns with attribute-based access control enforcement
Privileged-based Authorization (CNSC-9) · NIST AC-3(7) — Workload authorization based on pre-assigned roles and permissions aligns with role-based access control enforcement
CNSC-10relates-toAC-3(13)
AC-3(7)
ABAC and RBAC (CNSC-10) · NIST AC-3(13) — ABAC enforces access decisions based on workload and environmental attributes
ABAC and RBAC (CNSC-10) · NIST AC-3(7) — RBAC enforces access decisions based on pre-defined role assignments
CNSC-11relates-toAC-24Authorization and Identity Management (CNSC-11) · NIST AC-24 — Forwarded identity context enables dynamic authorization decisions at each service boundary
CNSC-12relates-toIA-2Cluster Authentication Management (CNSC-12) · NIST IA-2 — Cluster and workload operators are organizational users requiring unique identification and authentication
CNSC-13relates-toAC-3Authentication Policy Management (CNSC-13) · NIST AC-3 — Operator actions are evaluated against access control policies governing context, purpose, and output
CNSC-14relates-toIA-2(1)
IA-2(2)
Multi-factor Authentication (CNSC-14) · NIST IA-2(1) — Identity federation requiring MFA applies to privileged account access
Multi-factor Authentication (CNSC-14) · NIST IA-2(2) — Identity federation requiring MFA applies to non-privileged account access
CNSC-15relates-toSC-12(1)
SC-3(1)
HSMs Protection of Cryptographic Secrets (CNSC-15) · NIST SC-12(1) — HSMs provide hardware-based key storage and management for cryptographic secret protection
HSMs Protection of Cryptographic Secrets (CNSC-15) · NIST SC-3(1) — HSMs enforce hardware separation of cryptographic security functions from the general-purpose environment
CNSC-16relates-toSI-12Secrets Management (CNSC-16) · NIST SI-12 — Short expiration periods enforce timely disposal of secrets as a retention lifecycle policy
CNSC-17relates-toIA-5Secrets Lifecycle Management (CNSC-17) · NIST IA-5 — Verification of secret expiration and TTL prevents reuse of stale authenticators
CNSC-18relates-toSC-12(1)Secrets Management System (CNSC-18) · NIST SC-12(1) — Secrets management system availability ensures continuous access to cryptographic key infrastructure
CNSC-19relates-toIA-5Secrets Rotation Management (CNSC-19) · NIST IA-5 — Periodic rotation and revocation of long-lived secrets is an authenticator management lifecycle activity
CNSC-20relates-toSC-8Secrets Protection (CNSC-20) · NIST SC-8 — Secrets distributed through communication channels require transmission confidentiality and integrity proportional to sensitivity
CNSC-21relates-toAU-9Secret Injection Lifecycle (CNSC-21) · NIST AU-9 — Runtime secrets are masked or excluded to protect audit information from credential exposure
CNSC-22relates-toSI-7(9)Compute Bootstrapping Verification (CNSC-22) · NIST SI-7(9) — Bootstrapping verification of compute location is a boot process integrity check
CNSC-23relates-toSC-39
SC-7(21)
Boundary Management (CNSC-23) · NIST SC-39 — Workloads with different data sensitivity classifications require separate kernel-level execution domains
Boundary Management (CNSC-23) · NIST SC-7(21) — Isolation of workload components based on data sensitivity classification
CNSC-24relates-toCM-2(2)
CM-3(7)
Runtime Configuration Monitoring (CNSC-24) · NIST CM-2(2) — Automated detection of runtime configuration drift from the established baseline
Runtime Configuration Monitoring (CNSC-24) · NIST CM-3(7) — Runtime configuration changes are reviewed and correlated against authorized modifications
CNSC-25relates-toAU-2API Auditing Implementation (CNSC-25) · NIST AU-2 — Filtered API auditing defines the specific events and verbs captured for logging
CNSC-26relates-toCM-2
CM-7
Operating System Configuration (CNSC-26) · NIST CM-2 — Container-specific operating systems establish a purpose-built hardened baseline
Operating System Configuration (CNSC-26) · NIST CM-7 — Container-specific operating systems remove unnecessary services and functionality by design
CNSC-27relates-toSI-7Trust Implementation (CNSC-27) · NIST SI-7 — TPM and vTPM provide a hardware root of trust for software and firmware integrity verification
CNSC-28relates-toAC-6Least Privilege (CNSC-28) · NIST AC-6 — Minimizing administrative access to the control plane applies the principle of least privilege
CNSC-29relates-toSC-6
SC-39
Resource Control Management (CNSC-29) · NIST SC-6 — Cgroup resource requests and limits enforce allocation boundaries to prevent resource exhaustion
Resource Control Management (CNSC-29) · NIST SC-39 — Cgroups provide process-level isolation of resource consumption between workloads
CNSC-30relates-toSI-4(13)System Alert Monitoring (CNSC-30) · NIST SI-4(13) — Alert tuning for false positives refines traffic and event pattern analysis effectiveness
CNSC-31relates-toIA-9
SC-12
Control Plane Configuration (CNSC-31) · NIST IA-9 — Control plane components use mutual authentication and certificate validation to verify service identity
Control Plane Configuration (CNSC-31) · NIST SC-12 — Periodic certificate rotation for control plane communication is a key management lifecycle activity
CNSC-32relates-toCM-2
CM-7
Baseline Configured Functionality (CNSC-32) · NIST CM-2 — Seccomp filters define a baseline of sanctioned system calls for container execution
Baseline Configured Functionality (CNSC-32) · NIST CM-7 — Restricting container capabilities and system calls enforces least functionality
CNSC-33relates-toCM-5Critical Change Management (CNSC-33) · NIST CM-5 — Protecting critical mount points and files from unauthorized modification is an access restriction for change
CNSC-34relates-toCM-5Runtime Configuration for Change Management (CNSC-34) · NIST CM-5 — Runtime immutability of binaries, certificates, and remote access configurations restricts unauthorized change
CNSC-35relates-toSC-7Runtime Boundary Protection Management (CNSC-35) · NIST SC-7 — Container-level ingress and egress restrictions enforce network boundary protection at runtime
CNSC-36relates-toSC-7Boundary Protection Management (CNSC-36) · NIST SC-7 — Microservice communication allow-listing is application-layer network segmentation
CNSC-37relates-toCM-14Policy Enforcement Management (CNSC-37) · NIST CM-14 — Policy agents enforcing image signatures validate that only signed components are admitted
CNSC-38relates-toSR-4(3)Policy Enforcement Management (CNSC-38) · NIST SR-4(3) — Policy agents enforce provenance validation to confirm workload origin and integrity
CNSC-39relates-toSC-8Data Trust Management (CNSC-39) · NIST SC-8 — Service mesh encryption of data in transit protects transmission confidentiality and integrity
CNSC-40relates-toSI-4System Monitoring Components (CNSC-40) · NIST SI-4 — Container-level observation of system calls and network traffic implements system monitoring
CNSC-41relates-toSI-3Dynamic Workload Scanning (CNSC-41) · NIST SI-3 — Dynamic behavioral scanning detects zero-day and previously unknown malicious activity in running workloads
CNSC-42relates-toRA-5Continuous Monitoring and Scanning (CNSC-42) · NIST RA-5 — Continuous environment scanning for workload vulnerabilities is a vulnerability monitoring activity
CNSC-43relates-toAU-3Audit Event Logging (CNSC-43) · NIST AU-3 — Sufficient audit record content is a prerequisite for log correlation and incident response decision-making
CNSC-44relates-toAC-6
AC-5
Privilege Management (CNSC-44) · NIST AC-6 — Least privilege limits workload and operator permissions to the minimum required
Privilege Management (CNSC-44) · NIST AC-5 — Segregation of duties prevents any single actor from controlling an entire critical function
CNSC-45relates-toSI-7Information Integrity (CNSC-45) · NIST SI-7 — Policy-based violation detection verifies system state integrity against organizational rules
CNSC-46relates-toSC-12Key Management Storage (CNSC-46) · NIST SC-12 — External KMS integration for native secret store encryption is a key management infrastructure decision
CNSC-47relates-toSC-28(1)Secret Storage Configuration (CNSC-47) · NIST SC-28(1) — Secret stores must use cryptographic protection rather than encoding for data at rest
CNSC-48relates-toSI-4System Monitoring (CNSC-48) · NIST SI-4 — Detection and denial of traffic to malicious domains is network-level system monitoring
CNSC-49relates-toSC-28Sensitive Data Encryption (CNSC-49) · NIST SC-28 — Encrypted containers protect sensitive data at rest within container images and filesystems
CNSC-50relates-toCM-8SBOM Management (CNSC-50) · NIST CM-8 — SBOMs serve as a machine-readable component inventory for identifying vulnerable dependencies
CNSC-51relates-toCM-2
CM-7
Functionality Management (CNSC-51) · NIST CM-2 — Function allow-listing defines a baseline of permitted process execution
Functionality Management (CNSC-51) · NIST CM-7 — Restricting processes to explicitly allowed functions enforces least functionality
CNSC-52relates-toCM-5Access and Change Restrictions (CNSC-52) · NIST CM-5 — Preventing function-level modifications to critical filesystem mount points is an access restriction for change
CNSC-53relates-toAC-3Access Configuration (CNSC-53) · NIST AC-3 — Restricting function access to sanctioned services enforces service-level access control
CNSC-54relates-toSI-4System Monitoring (CNSC-54) · NIST SI-4 — Egress monitoring for command and control traffic detects compromised workload communication
CNSC-55relates-toSI-4System Monitoring Management (CNSC-55) · NIST SI-4 — Ingress inspection for malicious payloads and commands is inbound network monitoring
CNSC-56relates-toSC-7(21)System Component Isolation (CNSC-56) · NIST SC-7(21) — Tenant-based isolation of serverless functions by data classification implements component isolation
CNSC-57relates-toSR-4(3)
SR-4(4)
Trust Confirmation (CNSC-57) · NIST SR-4(3) — Image signature verification confirms the artifact is genuine and unaltered
Trust Confirmation (CNSC-57) · NIST SR-4(4) — Validating the signature source traces the artifact back to an authorized origin
CNSC-58relates-toCM-4Runtime Policy Enforcement (CNSC-58) · NIST CM-4 — Pre-deployment policy enforcement gates image admission on integrity and trust criteria
CNSC-59relates-toSR-4(3)
SR-4(4)
Image Integrity Verification (CNSC-59) · NIST SR-4(3) — Pre-deployment integrity verification confirms the image has not been altered
Image Integrity Verification (CNSC-59) · NIST SR-4(4) — Pre-deployment signature verification traces the image to its authorized build origin
CNSC-60relates-toAU-2
AU-3
Application Logging (CNSC-60) · NIST AU-2 — Authentication, authorization, action, and failure events are identified for application logging
Application Logging (CNSC-60) · NIST AU-3 — Application logs include authentication, authorization, action, and failure content
CNSC-62relates-toSI-3Behavioral Analysis (CNSC-62) · NIST SI-3 — AI/ML-based heuristic analysis extends malicious code detection beyond signature-based methods
CNSC-63relates-toSA-3(1)Production Environment (CNSC-63) · NIST SA-3(1) — A dedicated production environment implies managed separation from preproduction stages
CNSC-64relates-toSA-8(31)Dynamic Deployments (CNSC-64) · NIST SA-8(31) — Dynamic deployment strategies (canary, blue-green, rolling) are secure system modification techniques
CNSC-65relates-toSA-11(1)Early Vulnerability Scanning (CNSC-65) · NIST SA-11(1) — IDE and pull request scanning shifts static analysis to the earliest point in the development lifecycle
CNSC-66relates-toSA-15Environment Segregation (CNSC-66) · NIST SA-15 — Segregation of development, testing, and production environments is a development process standard
CNSC-67relates-toSA-11Business-Critical Code Testing (CNSC-67) · NIST SA-11 — Testing business-critical code is a developer evaluation activity
CNSC-68relates-toSA-11Infrastructure Testing (CNSC-68) · NIST SA-11 — Testing business-critical infrastructure is a developer evaluation activity
CNSC-69relates-toSA-11Local Test Execution (CNSC-69) · NIST SA-11 — Local test execution enables developer evaluation before code integration
CNSC-70relates-toSA-11Shared Test Execution (CNSC-70) · NIST SA-11 — Shared test environments enable collaborative developer evaluation
CNSC-71relates-toSA-11(4)Code Review Requirements (CNSC-71) · NIST SA-11(4) — Non-author code review is a manual evaluation gate prior to integration
CNSC-73relates-toSA-11Full Infrastructure Testing (CNSC-73) · NIST SA-11 — Full infrastructure testing validates the complete deployment target
CNSC-74relates-toSA-11Regression Testing (CNSC-74) · NIST SA-11 — Regression testing verifies existing functionality is preserved after changes
CNSC-75relates-toSA-11Security Regression Testing (CNSC-75) · NIST SA-11 — Security regression tests evolve developer evaluation against emerging threats
CNSC-76relates-toSA-3(1)Testing Environment (CNSC-76) · NIST SA-3(1) — A dedicated testing environment is a managed preproduction stage in the development lifecycle
CNSC-77relates-toSC-39CI Server Isolation (CNSC-77) · NIST SC-39 — CI server isolation prevents build processes from affecting or being affected by other workloads
CNSC-78relates-toSA-11(2)Threat-Informed Test Development (CNSC-78) · NIST SA-11(2) — Threat model results inform test development priorities and investment decisions
CNSC-85relates-toRA-5Manifest Scanning (CNSC-85) · NIST RA-5 — Manifest scanning in CI detects vulnerabilities in declared dependencies before deployment
CNSC-86relates-toSC-39CI Server Isolation (CNSC-86) · NIST SC-39 — Isolating CI servers for sensitive workloads prevents cross-contamination of build processes
CNSC-87relates-toSC-39Privileged Build Isolation (CNSC-87) · NIST SC-39 — Dedicating servers for privileged builds isolates elevated-privilege execution from other processes
CNSC-88relates-toSA-1Build Policy Enforcement (CNSC-88) · NIST SA-1 — Build policy enforcement establishes CI pipeline governance procedures
CNSC-89relates-toSI-7Pipeline Metadata Signing (CNSC-89) · NIST SI-7 — Signed pipeline metadata ensures integrity of build process records
CNSC-90relates-toSI-7Build Stage Verification (CNSC-90) · NIST SI-7 — Stage-gate verification ensures integrity is maintained between build phases
CNSC-91relates-toRA-5CI Pipeline Scanning (CNSC-91) · NIST RA-5 — CI pipeline image scanning detects vulnerabilities before artifacts leave the build process
CNSC-92relates-toSA-1Pipeline Compliance Integration (CNSC-92) · NIST SA-1 — Coupling vulnerability scans with compliance rules integrates security into pipeline procedures
CNSC-93relates-toSA-11(8)Dynamic Application Security Testing (CNSC-93) · NIST SA-11(8) — DAST validates application security through runtime interaction testing
CNSC-94relates-toSI-4Application Instrumentation (CNSC-94) · NIST SI-4 — Application instrumentation provides runtime observability for system monitoring
CNSC-97relates-toSI-4Security Health Verification (CNSC-97) · NIST SI-4 — Build and deploy-time security health checks are automated monitoring gates
CNSC-99relates-toCA-8
SA-11
Automated Security Testing (CNSC-99) · NIST CA-8 — Automated security testing includes penetration testing techniques
Automated Security Testing (CNSC-99) · NIST SA-11 — Automation of security testing ensures consistent developer evaluation
CNSC-100relates-toIA-3(1)Registry Authentication (CNSC-100) · NIST IA-3(1) — Mutual TLS for registry connections requires cryptographic bidirectional device authentication
CNSC-101relates-toSI-7Image Signing (CNSC-101) · NIST SI-7 — Signing images and metadata provides integrity verification for distributed artifacts
CNSC-102relates-toSI-7Configuration Signing (CNSC-102) · NIST SI-7 — Signed configuration prevents unauthorized modification of workload settings
CNSC-103relates-toSI-7Package Signing (CNSC-103) · NIST SI-7 — Signed packages provide integrity verification for distributed software
CNSC-104relates-toSI-7Image Integrity Validation (CNSC-104) · NIST SI-7 — Image integrity validation detects unauthorized modification of container artifacts
CNSC-105relates-toRA-5
SA-3
Image Vulnerability Scanning (CNSC-105) · NIST RA-5 — Image scanning detects known vulnerabilities and malware in container artifacts
Image Vulnerability Scanning (CNSC-105) · NIST SA-3 — Vulnerability scanning of images is integrated into the development lifecycle
CNSC-106relates-toSC-12Key Revocation (CNSC-106) · NIST SC-12 — Key revocation invalidates trust in artifacts signed by compromised keys
CNSC-107relates-toSI-2(3)Security Update Prioritization (CNSC-107) · NIST SI-2(3) — Prioritizing security updates is a flaw remediation scheduling activity
CNSC-108relates-toSC-12(3)Credential Protection (CNSC-108) · NIST SC-12(3) — HSMs provide asymmetric key infrastructure for credential protection
CNSC-109relates-toSI-2(3)Scanning Remediation (CNSC-109) · NIST SI-2(3) — Acting on container image scanning findings is flaw remediation
CNSC-110relates-toPL-1Compliance Enforcement (CNSC-110) · NIST PL-1 — Enforcing organizational compliance rules is a planning and policy activity
CNSC-112relates-toAC-6(3)Public Registry Access Control (CNSC-112) · NIST AC-6(3) — Restricting public registry pulls to authorized engineers enforces network access to privileged commands
CNSC-113relates-toSC-12(2)
SC-12(3)
Image Encryption Management (CNSC-113) · NIST SC-12(2) — Image encryption uses symmetric keys for bulk data protection
Image Encryption Management (CNSC-113) · NIST SC-12(3) — Key attestation and credential distribution use asymmetric keys for authorization
CNSC-114relates-toSI-2(3)Risk-Based Remediation Prioritization (CNSC-114) · NIST SI-2(3) — Risk-based prioritization using exploit maturity and vulnerable paths refines flaw remediation scheduling
CNSC-115relates-toAC-6(3)East-West Network Policy (CNSC-115) · NIST AC-6(3) — East-west network policies restrict lateral communication to authorized network-level privileged commands
CNSC-116relates-toCA-7
IR-4
IR-4(5)
Incident Response (CNSC-116) · NIST CA-7 — Cloud native incident response requires continuous monitoring of workload behavior
Incident Response (CNSC-116) · NIST IR-4 — Incident handling processes must account for cloud native workload dynamics
Incident Response (CNSC-116) · NIST IR-4(5) — Automated disabling of compromised cloud native workloads
CNSC-117relates-toIR-5(1)Incident Monitoring (CNSC-117) · NIST IR-5(1) — Evidence handling and collection for cloud native workloads requires automated tracking and data collection
CNSC-120relates-toAC-3(3)Mandatory Access Controls (CNSC-120) · NIST AC-3(3) — MAC implementations enforce mandatory access control policies
CNSC-121relates-toSA-11(2)Threat Modeling and Vulnerability Analysis (CNSC-121) · NIST SA-11(2) — Threat modeling of code and infrastructure informs vulnerability analysis
CNSC-122relates-toIA-9Authentication Management (CNSC-122) · NIST IA-9 — Independent authentication of entity identities is service-level identification and authentication
CNSC-123relates-toIA-9Identity Management (CNSC-123) · NIST IA-9 — Proof of identity creation enables service identification and authentication
CNSC-124relates-toCM-14Trusted Components (CNSC-124) · NIST CM-14 — Trusted OS and BIOS for orchestrators requires signed and verified system components
CNSC-125relates-toSI-6Security Verification (CNSC-125) · NIST SI-6 — Verifying container claims is a security function verification activity
CNSC-127relates-toSC-8Control Plane Authentication (CNSC-127) · NIST SC-8 — Mutual authentication and TLS for control plane connections protects transmission confidentiality and integrity
CNSC-128relates-toSI-13Data Availability Mechanism (CNSC-128) · NIST SI-13 — Parity, mirroring, and replicas are predictable failure prevention mechanisms for data availability
CNSC-129relates-toCM-7
SI-7
Integrity Validation (CNSC-129) · NIST CM-7 — Checksums constrain storage to validated data, supporting least functionality
Integrity Validation (CNSC-129) · NIST SI-7 — Hashing and checksums verify data integrity
CNSC-130relates-toSA-9Data Source Storage Management (CNSC-130) · NIST SA-9 — Backup locations with equivalent security controls are managed as external system services
CNSC-131relates-toCP-9
MP-6
System Backup (CNSC-131) · NIST CP-9 — Data is backed up before device disposition
System Backup (CNSC-131) · NIST MP-6 — OPAL-standard erasure of returned devices is media sanitization
CNSC-132relates-toSC-28Encryption of Data at Rest (CNSC-132) · NIST SC-28 — Data-at-rest encryption decisions based on access patterns align with protection of information at rest
CNSC-135relates-toCM-6
SA-8
SC-7
Security Policy Management (CNSC-135) · NIST CM-6 — Volume mount access restrictions are configuration settings
Security Policy Management (CNSC-135) · NIST SA-8 — Volume access restrictions implement security engineering isolation principles
Security Policy Management (CNSC-135) · NIST SC-7 — Preventing container access to worker node volumes is boundary protection
CNSC-136relates-toCM-6
SA-8
SC-7
Security Policy Enforcement (CNSC-136) · NIST CM-6 — Enforced volume access policies are configuration settings
Security Policy Enforcement (CNSC-136) · NIST SA-8 — Authorized volume access enforcement applies security engineering principles
Security Policy Enforcement (CNSC-136) · NIST SC-7 — Worker node volume access restrictions enforce boundary protection
CNSC-137relates-toAC-16
AC-4
SI-7
Information Flow Management (CNSC-137) · NIST AC-16 — Volume UID/GID are security attributes controlling access scope
Information Flow Management (CNSC-137) · NIST AC-4 — Restricting UID/GID access enforces information flow between containers and volumes
Information Flow Management (CNSC-137) · NIST SI-7 — Protecting volume UID/GID from container access preserves file system integrity
CNSC-139relates-toCM-14Signed Artifact Support (CNSC-139) · NIST CM-14 — Registry support for signed artifacts enables component signature verification
CNSC-140relates-toAU-10
CM-6
Artifact Registry Policy Verification (CNSC-140) · NIST AU-10 — Policy-based artifact verification provides a non-repudiation mechanism
Artifact Registry Policy Verification (CNSC-140) · NIST CM-6 — Organizational artifact policies are configuration settings enforced by the registry
CNSC-141relates-toSI-1
SI-7
Build Process Attestation (CNSC-141) · NIST SI-1 — Build process attestation establishes integrity policy for each pipeline stage
Build Process Attestation (CNSC-141) · NIST SI-7 — Signing each build step provides verifiable integrity of the build process
CNSC-142relates-toSI-1
SI-7
Build Signature Verification (CNSC-142) · NIST SI-1 — Verifying signatures at each build step enforces integrity policy compliance
Build Signature Verification (CNSC-142) · NIST SI-7 — Signature verification at each stage detects unauthorized modification of build artifacts
CNSC-143relates-toIA-5Artifact Signing Framework (CNSC-143) · NIST IA-5 — The signing framework manages cryptographic authenticators for artifact identity
CNSC-144relates-toAC-4(6)Attestation Store (CNSC-144) · NIST AC-4(6) — Attestation metadata controls information flow decisions about artifact provenance
CNSC-145relates-toAC-6Certification Authorization (CNSC-145) · NIST AC-6 — Limiting certification authority applies the principle of least privilege to artifact signing
CNSC-146relates-toSC-12Key Rotation and Revocation (CNSC-146) · NIST SC-12 — Private key rotation and revocation are key management lifecycle activities
CNSC-148relates-toIA-5
SC-12
SC-13
SC-28(1)
SC-8
Artifact Encryption (CNSC-148) · NIST IA-5 — Decryption capabilities are managed as platform authenticators
Artifact Encryption (CNSC-148) · NIST SC-12 — Encryption keys require lifecycle management
Artifact Encryption (CNSC-148) · NIST SC-13 — Artifact encryption uses approved cryptographic mechanisms
Artifact Encryption (CNSC-148) · NIST SC-28(1) — Encrypted artifacts at rest use cryptographic protection
Artifact Encryption (CNSC-148) · NIST SC-8 — Encrypted distribution protects artifact confidentiality and integrity in transit
CNSC-149relates-toCM-3(6)Cryptographic Policy Guarantee (CNSC-149) · NIST CM-3(6) — Cryptographic guarantees of policy adherence provide tamper-evident configuration change control
CNSC-150relates-toCM-3(2)Environment and Dependency Validation (CNSC-150) · NIST CM-3(2) — Validating environments and dependencies before usage tests configuration changes for impact
CNSC-151relates-toCM-3(4)Build Worker Runtime Security (CNSC-151) · NIST CM-3(4) — Build worker runtime security validation is an automated security response to configuration changes
CNSC-152relates-toCM-3(4)Reproducible Builds (CNSC-152) · NIST CM-3(4) — Reproducible builds provide automated verification of configuration change outcomes
CNSC-153relates-toCM-3(2)External Requirement Verification (CNSC-153) · NIST CM-3(2) — Locking and verifying external requirements tests configuration changes for impact before execution
CNSC-155relates-toCM-3(1)Build Environment Recording (CNSC-155) · NIST CM-3(1) — Recording the build environment provides automated documentation of configuration changes
CNSC-156relates-toCM-3(3)Build Environment Automation (CNSC-156) · NIST CM-3(3) — Automated build environment creation implements automated change implementation mechanisms
CNSC-157relates-toCM-3(3)Build Distribution (CNSC-157) · NIST CM-3(3) — Distributing builds across infrastructure uses automated change mechanisms to reduce single points of failure
CNSC-158relates-toSA-3Pipeline as Code (CNSC-158) · NIST SA-3 — Pipeline-as-code defines the system development lifecycle for build automation
CNSC-161relates-toAC-2Single-Use Build Workers (CNSC-161) · NIST AC-2 — Single-use build workers enforce ephemeral account management for build processes
CNSC-162relates-toSC-7(3)Software Factory Network Isolation (CNSC-162) · NIST SC-7(3) — Minimal network connectivity for the software factory restricts access points as boundary protection
CNSC-163relates-toAC-5Build Worker Duty Segregation (CNSC-163) · NIST AC-5 — Segregating build worker duties enforces separation of duties in the build pipeline
CNSC-164relates-toCM-2(2)Build Worker Environment Control (CNSC-164) · NIST CM-2(2) — Passing in environment and commands enforces baseline configuration through automation
CNSC-165relates-toAU-9(2)Secured Output Storage (CNSC-165) · NIST AU-9(2) — Secured output storage protects build audit information in a separate repository
CNSC-167relates-toAC-2User Role Definition (CNSC-167) · NIST AC-2 — Defining user roles for the build pipeline is an account management activity
CNSC-168relates-toSC-17Root of Trust Establishment (CNSC-168) · NIST SC-17 — Offline root of trust establishment aligns with PKI certificate management practices
CNSC-169relates-toSC-23(5)Short-Lived Certificates (CNSC-169) · NIST SC-23(5) — Short-lived workload certificates enforce session authenticity with time-bound validity
CNSC-170relates-toSI-7Artifact Verification (CNSC-170) · NIST SI-7 — Client-side artifact verification confirms integrity before consumption
CNSC-171relates-toSI-7Freshness Verification (CNSC-171) · NIST SI-7 — Freshness verification detects stale or replayed artifacts
CNSC-173relates-toSA-11Third-Party Artifact Verification (CNSC-173) · NIST SA-11 — Verification of third-party artifacts is a supply chain evaluation activity
CNSC-174relates-toCM-8Third-Party SBOM Requirements (CNSC-174) · NIST CM-8 — Third-party SBOMs provide component inventory for supply chain transparency
CNSC-175relates-toCM-10Dependency Tracking (CNSC-175) · NIST CM-10 — Tracking open source component dependencies enforces software usage restrictions
CNSC-179relates-toRA-5Software Vulnerability Scanning (CNSC-179) · NIST RA-5 — Software vulnerability scanning identifies known weaknesses in third-party materials
CNSC-180relates-toCM-10License Compliance Scanning (CNSC-180) · NIST CM-10 — License compliance scanning enforces software usage restrictions for legal compliance
CNSC-181relates-toSA-11(1)Software Composition Analysis (CNSC-181) · NIST SA-11(1) — SCA combines static analysis to evaluate ingested software
CNSC-182relates-toSI-7Commit and Tag Signing (CNSC-182) · NIST SI-7 — Signed commits and tags establish integrity and authorship of source code changes
CNSC-183relates-toAC-6(3)Branch Protection Attestation (CNSC-183) · NIST AC-6(3) — Attestation enforcement for protected branches restricts code modification to authorized privileged commands
CNSC-184relates-toSC-12(3)Secret Commit Prevention (CNSC-184) · NIST SC-12(3) — Encrypting secrets before repository commit requires asymmetric key infrastructure
CNSC-185relates-toPL-1Repository Access Definition (CNSC-185) · NIST PL-1 — Defining repository write access is an access planning and policy activity
CNSC-186relates-toRA-5Automated Security Scanning (CNSC-186) · NIST RA-5 — Automation of security scanning ensures consistent vulnerability detection in source code
CNSC-187relates-toPL-1Contribution Policy Enforcement (CNSC-187) · NIST PL-1 — Contribution policies establish governance procedures for source code changes
CNSC-188relates-toPL-1Functional Role Definition (CNSC-188) · NIST PL-1 — Defining roles aligned to functional responsibilities is a planning and policy activity
CNSC-189relates-toSA-11Four-Eyes Principle (CNSC-189) · NIST SA-11 — The four-eyes principle ensures independent evaluation of code changes
CNSC-190relates-toSA-8Branch Protection Rules (CNSC-190) · NIST SA-8 — Branch protection rules implement security engineering principles for source code governance
CNSC-191relates-toIA-2(1)Repository MFA Enforcement (CNSC-191) · NIST IA-2(1) — Repository MFA enforcement requires multi-factor authentication for organizational users accessing source code
CNSC-192relates-toAC-1SSH Key Access (CNSC-192) · NIST AC-1 — SSH key-based access to repositories implements access control procedures for developer authentication
CNSC-193relates-toAC-2(1)Key Rotation Policy (CNSC-193) · NIST AC-2(1) — Key rotation policy defines prerequisites for automated credential management
CNSC-194relates-toAC-2(1)Ephemeral Credentials (CNSC-194) · NIST AC-2(1) — Ephemeral credentials automate credential lifecycle management for machine and service accounts
CNSC-195relates-toSA-8(23)Secure Configuration Defaults (CNSC-195) · NIST SA-8(23) — Secure default configuration implements the secure defaults engineering principle
CNSC-208relates-toIA-2(1)
IA-2(2)
Multi-factor Authentication (CNSC-208) · NIST IA-2(1) — Identity federation with MFA requires multi-factor authentication for privileged users
Multi-factor Authentication (CNSC-208) · NIST IA-2(2) — Identity federation with MFA requires multi-factor authentication for non-privileged users
CNSC-233relates-toSC-7Data Trust Management (CNSC-233) · NIST SC-7 — Service mesh data-in-motion protection establishes boundary protection through confidentiality, integrity, and authentication
CNSC-259relates-toSA-11(1)Early Vulnerability Scanning (CNSC-259) · NIST SA-11(1) — Integrating scanning in IDE and CI during pull request shifts static analysis left
CNSC-265relates-toSA-11(4)Code Review Requirements (CNSC-265) · NIST SA-11(4) — Requiring a non-author reviewer prior to merging is a manual code review gate
CNSC-271relates-toSC-39CI Server Isolation (CNSC-271) · NIST SC-39 — CI server isolation and hardening prevents compromise of build infrastructure
CNSC-297relates-toSI-7Configuration Signing (CNSC-297) · NIST SI-7 — Signed workload configuration prevents unauthorized modification
CNSC-298relates-toSI-7Package Signing (CNSC-298) · NIST SI-7 — Signed workload packages provide integrity verification for deployment artifacts
CNSC-303relates-toSC-12(3)Credential Protection (CNSC-303) · NIST SC-12(3) — HSMs or software credential managers protect asymmetric keys for stored credentials