Control Evidence Mappings
Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.
Published (40)
AC-1: Establish access control policy and procedures for organizational systems
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-2: Manage system accounts including establishment, activation, modification, review, disabling, and removal
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-3: Enforce approved authorizations for logical access to information and system resources
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-4: Enforce approved authorizations for controlling the flow of information within the system and between systems
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-5: Separate duties of individuals to reduce risk of malevolent activity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-7: Enforce a limit of consecutive invalid logon attempts and take action when maximum is exceeded
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-8: Display system use notification message before granting access
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-11: Prevent further access to the system by initiating a session lock after a defined period of inactivity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-12: Automatically terminate a user session after defined conditions
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-14: Identify permitted actions without identification or authentication
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AC-17: Establish usage restrictions and implementation guidance for remote access
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-1: Develop and document audit and accountability policy and procedures
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-2: Identify events that the system must be capable of auditing
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-3: Ensure audit records contain sufficient information to establish what occurred, when, where, source, outcome, and identity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-4: Allocate audit log storage capacity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-5: Alert personnel or take action upon audit logging process failures
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-6: Review and analyze audit records for indications of inappropriate or unusual activity
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-7: Provide audit record reduction and report generation capability
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-8: Use internal system clocks to generate time stamps for audit records
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-9: Protect audit information and audit logging tools from unauthorized access, modification, and deletion
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-10: Provide irrefutable evidence that actions were performed (non-repudiation)
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-11: Retain audit records for a defined period to support after-the-fact investigations
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
AU-12: Provide audit record generation capability at system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CA-2: Develop and implement security assessment plans
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CA-7: Develop and implement a system-level continuous monitoring strategy
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-2: Develop, document, and maintain a current baseline configuration of the system
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-3: Determine and document types of changes to the system that are configuration-controlled
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-6: Establish and document configuration settings for system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
CM-8: Develop and document an inventory of system components
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-2: Uniquely identify and authenticate organizational users
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-4: Manage system identifiers by receiving authorization, selecting, assigning, and preventing reuse
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-5: Manage system authenticators including initial distribution, lost/compromised handling, and revocation
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
IA-8: Uniquely identify and authenticate non-organizational users
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-4: Prevent unauthorized and unintended information transfer via shared system resources
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-7: Monitor and control communications at external managed interfaces
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-8: Protect the confidentiality and integrity of transmitted information
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-12: Establish and manage cryptographic keys
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-13: Implement cryptographic mechanisms in accordance with applicable laws and policies
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
SC-28: Protect the confidentiality and integrity of information at rest
NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED
In Progress (4)
These mappings are under editorial review and will be published after quality verification.
SI-4: Monitor the system to detect attacks, indicators of potential attacks, and unauthorized connections
NIST SP 800-53 · Under review
SI-7: Employ integrity verification tools to detect unauthorized changes to software, firmware, and information
NIST SP 800-53 · Under review
SI-10: Check the validity of information inputs
NIST SP 800-53 · Under review
SI-12: Manage and retain information within the system and output from the system in accordance with policies
NIST SP 800-53 · Under review