Framework library

Activate as many standards as you need. Attesta records the framework version, creates the applicable requirements, and connects them to canonical controls so one implementation is never rebuilt twice.

CMMC

Certification

Cybersecurity Maturity Model Certification

Maturity levels for protecting federal contract information and controlled unclassified information.

Version
2.0
Authority
US DoD

FedRAMP

Authorization

FedRAMP Moderate Baseline

Standardised security authorization baseline for cloud services used by US federal agencies.

Version
Rev. 5 Moderate
Authority
GSA / FedRAMP PMO

GDPR

Regulation

EU General Data Protection Regulation

Obligations for lawful, secure and accountable processing of personal data of EU data subjects.

Version
2016/679
Authority
European Union

HIPAA

Regulation

HIPAA Security Rule

Administrative, physical and technical safeguards for electronic protected health information.

Version
45 CFR Part 164
Authority
US HHS

HITRUST

Certification

HITRUST CSF

Prescriptive, risk-based control framework harmonising multiple healthcare and security standards.

Version
v11
Authority
HITRUST Alliance

ISO 27001

Certification

ISO/IEC 27001 Information Security Management

Requirements for establishing, maintaining and continually improving an information security management system.

Version
2022
Authority
ISO/IEC

ISO 42001

Certification

ISO/IEC 42001 AI Management System

Requirements for an artificial intelligence management system, including AI risk and impact assessment.

Version
2023
Authority
ISO/IEC

NIST 800-53

Control Catalogue

NIST SP 800-53 Security and Privacy Controls

Comprehensive catalogue of security and privacy controls for information systems and organizations.

Version
Rev. 5
Authority
NIST

NIST CSF

Framework

NIST Cybersecurity Framework

Govern, Identify, Protect, Detect, Respond and Recover outcomes for managing cybersecurity risk.

Version
2.0
Authority
NIST

PCI DSS

Certification

Payment Card Industry Data Security Standard

Requirements for protecting cardholder data in payment environments.

Version
4.0.1
Authority
PCI SSC

SOC 2

Attestation

SOC 2 Trust Services Criteria

Trust services criteria for security, availability, processing integrity, confidentiality and privacy.

Version
2017 TSC (rev. 2022)
Authority
AICPA

Canonical control set

44 maintained controls sit underneath the frameworks. Attesta only claims a control satisfies a framework when a maintained mapping exists.

Canonical controls and their domains
ControlDomainDescription
CC-ACC-01

Unique user identification

Access ControlEvery person and service accessing systems is assigned a unique, attributable identifier.
CC-ACC-02

Multi-factor authentication

Access ControlMulti-factor authentication is enforced for remote, administrative and privileged access.
CC-ACC-03

Least-privilege access provisioning

Access ControlAccess is granted on a documented, role-based least-privilege basis and approved before issue.
CC-ACC-04

Periodic access review

Access ControlUser and privileged access rights are reviewed on a defined schedule and corrected where needed.
CC-ACC-05

Timely access revocation

Access ControlAccess is revoked promptly on termination or role change under a documented process.
CC-AIG-01

AI system inventory and impact assessment

AI GovernanceAI systems are inventoried and assessed for impact on individuals and the organization.
CC-AIG-02

AI oversight and human review

AI GovernanceHuman oversight, review and escalation are defined for AI-assisted decisions.
CC-AST-01

Asset inventory

Asset ManagementA current inventory of hardware, software, data stores and services is maintained with owners.
CC-AST-02

Data classification and handling

Asset ManagementInformation is classified and handled according to defined sensitivity levels.
CC-AST-03

Secure media and asset disposal

Asset ManagementMedia and assets are sanitised or destroyed securely before disposal or reuse.
CC-BCP-01

Backup and restoration

ResilienceBackups are performed, protected and restore-tested on a defined schedule.
CC-BCP-02

Business continuity and disaster recovery plan

ResilienceContinuity and recovery plans define objectives, responsibilities and recovery targets.
CC-BCP-03

Continuity plan testing

ResilienceContinuity and recovery plans are exercised periodically and results drive improvement.
CC-CHG-01

Change management

Change ManagementChanges are requested, reviewed, approved, tested and recorded before release.
CC-CHG-02

Secure development lifecycle

Change ManagementSecurity requirements, code review and testing are embedded in the development lifecycle.
CC-CHG-03

Environment separation

Change ManagementDevelopment, test and production environments are separated with controlled promotion.
CC-CRY-01

Encryption in transit

Data ProtectionData in transit is protected with current, strong cryptographic protocols.
CC-CRY-02

Encryption at rest

Data ProtectionSensitive data at rest is encrypted using approved algorithms and managed keys.
CC-CRY-03

Key management

Data ProtectionCryptographic keys are generated, stored, rotated and retired under a documented procedure.
CC-GOV-01

Information security policy set

GovernanceA management-approved policy set is maintained, communicated and reviewed at least annually.
CC-GOV-02

Security roles and responsibilities

GovernanceSecurity roles, responsibilities and accountable owners are defined and assigned.
CC-GOV-03

Risk assessment process

GovernanceRisks are identified, analysed, treated and reviewed under a documented, repeatable process.
CC-GOV-04

Management review of security programme

GovernanceLeadership reviews security performance, risks and improvement actions at planned intervals.
CC-HRS-01

Personnel screening

People SecurityBackground verification is performed for personnel proportionate to role and data access.
CC-HRS-02

Security awareness training

People SecurityPersonnel complete security and privacy awareness training at onboarding and periodically.
CC-HRS-03

Terms of employment and confidentiality

People SecurityEmployment terms include security responsibilities and confidentiality obligations.
CC-INC-01

Incident response plan

Incident ManagementA documented incident response plan defines roles, severity levels and escalation paths.
CC-INC-02

Incident detection and reporting

Incident ManagementPersonnel and systems have defined channels to report suspected security incidents.
CC-INC-03

Breach notification process

Incident ManagementRegulatory and contractual breach notification obligations are documented and exercised.
CC-OPS-01

Centralised logging

Security OperationsSecurity-relevant events are logged centrally, protected from tampering, and retained.
CC-OPS-02

Log review and alerting

Security OperationsLogs and alerts are monitored and investigated under a defined process.
CC-OPS-03

Endpoint protection

Security OperationsEndpoints run managed protective software with central visibility and enforcement.
CC-OPS-04

Network segmentation and boundary protection

Security OperationsNetwork boundaries are controlled and sensitive environments are segmented.
CC-PHY-01

Physical access control

Physical SecurityPhysical access to facilities and equipment is restricted, logged and reviewed.
CC-PHY-02

Mobile and portable device security

Physical SecurityMobile and portable devices are encrypted, managed and remotely wipeable.
CC-PRV-01

Lawful basis and privacy notices

PrivacyPersonal data processing has a documented lawful basis and transparent notices.
CC-PRV-02

Data subject rights handling

PrivacyRequests to access, correct, delete or port personal data are handled within required timeframes.
CC-PRV-03

Data minimisation and retention

PrivacyPersonal data is limited to what is necessary and deleted per a retention schedule.
CC-TPM-01

Third-party due diligence

Third-Party ManagementSuppliers are risk-assessed before engagement and re-assessed on a defined cycle.
CC-TPM-02

Contractual security requirements

Third-Party ManagementContracts include security, privacy and breach notification obligations.
CC-TPM-03

Ongoing supplier monitoring

Third-Party ManagementSupplier performance and security posture are monitored throughout the relationship.
CC-VUL-01

Vulnerability scanning

Vulnerability ManagementSystems are scanned for vulnerabilities on a defined schedule.
CC-VUL-02

Patch and remediation SLAs

Vulnerability ManagementVulnerabilities are remediated within severity-based timeframes and tracked to closure.
CC-VUL-03

Penetration testing

Vulnerability ManagementIndependent penetration testing is performed periodically and findings are remediated.