Closed andy-werderman closed 5 days ago
@andy-werderman Thanks for raising the issue.
We investigated from our end and found that Audit Manager has not yet published the NIST CSF 2.0 Benchmark. We strictly adhere to AWS Audit Manager.
Additionally, we were not able to find any relevant documentation with controls mapping for the NIST CSF 2.0 Benchmark.
Please let us know if you have any references for the controls. Thanks.
We investigated from our end and found that Audit Manager has not yet published the NIST CSF 2.0 Benchmark. We strictly adhere to AWS Audit Manager.
Ah that makes sense! I wasn't aware.
Additionally, we were not able to find any relevant documentation with controls mapping for the NIST CSF 2.0 Benchmark.
I think the documentation you are talking about is a mapping from the NIST CSF 2.0 benchmark control --> an actual control in the aws compliance mod, is that right??
I'm not aware of any documentation like that either.
All I know of is:
I should note that a lot of the controls are vague and in my mind wouldn't directly point to a specific API call or check in AWS. Only a subset could be verified by API calls to AWS.
I reached out to my company's AWS rep to ask about their support for NIST CSF 2.0. Here was his response:
I’ve heard back from the product team. Under NDA I can tell you that they have paused onboarding new frameworks until after re:Invent. I have added your influence to the request for NIST CSF v2.0 for when the team picks up the next round of frameworks.
This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 30 days.
Hi @andy-werderman
We are closing this issue for now since AWS Audit Manager hasn't released the NIST CSF 2.0 yet. We are closely monitoring the Audit Manager framework library, we will reopen the issue once the updates are available.
Thank you for your understanding!
Is your feature request related to a problem? Please describe. Nope, just an enhancement to current functionality.
Describe the solution you'd like Implementation of the new NIST CSF 2.0 Benchmark (updated from the current v1.1).
Describe alternatives you've considered None
Additional context NIST released a new version of the CIS benchmark in February. According to the links below, it seems the updates mostly reorganize existing controls as well as introduce a small few. In addition, the new controls seem to mostly be things handled outside of aws api calls. Most of the work here will probably be determining what needs to be done.
See slack thread in links below.
Related Links