NIST CSF Evidence Framing

United States NIST Cybersecurity Framework and 800-53 consumer mapping for remote script orchestration.

United States buyers map NIST CSF PR and DE functions to Trustholm audit export, IAM, and signing features-we do not claim FedRAMP or NIST certification.

NIST CSF Evidence Framing

Framework evidence framing before detailed tables below.

Financial services corporate towers representing regulated finance clients

Compliance framing

NIST CSF Evidence Framing

Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.

  • Reproduce audit export in trial
  • Download trust pack for binders
  • Regional hub cross-links
Gaprows published openly
Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

United States buyers evaluating MSP script orchestration often map NIST Cybersecurity Framework (CSF) functions and NIST SP 800-53 control families to SaaS subprocessors. Trustholm is a remote management and script execution platform-not a certified cloud service offering.

We supply consumer-side evidence for identify-protect-detect themes while your organization owns SSP content, continuous monitoring, and third-party risk management outcomes.

Identify and protect (PR)

PR.AC (Access Control): Portal users authenticate via JWT sessions with tenant binding for authenticated principals. Users and roles UI supports RBAC within tenant scope. MFA flows apply to privileged portal access where configured. SSO integrates via OIDC and SAML-your IdP remains the lifecycle authority for identities.

PR.DS (Data Security): Schema-per-tenant PostgreSQL separation namespaces tenant data. API middleware returns 403 when resolved tenant does not match JWT TenantId for portal users. Agents use tenant code headers and per-agent polling credentials-distinct from human SSO paths.

PR.IP (Information Protection): Signed PowerShell policy executes before run. Script publish and approve events land in the security audit plane with export for assessor windows.

Detect (DE)

DE.AE (Anomalies and Events): Security audit export provides JSON/CSV with category and datetime filters within documented row caps. HTTP request logs enriched with tenant_id support operational chargeback-they are not a substitute for security audit categories in compliance narratives.

DE.CM (Continuous Monitoring): Super Admin operators observe distributed rate limiting and health signals. Your team owns infrastructure monitoring, vulnerability management, and SIEM forwarding policies. Native Microsoft Sentinel connector remains backlog-do not imply shipped SIEM automation.

How US MSPs use Trustholm in vendor review

Include audit export slices, IAM screenshots, and Shipped/Gap evidence tables in your customer-facing vendor appendix. vCISOs pair our artifacts with pentest results, vulnerability scans, and customer-operated controls. When questionnaire authors ask for FedRAMP or NIST moderate baseline certification, clarify that Trustholm provides technical enabler artifacts-not authorization badges.

Gap honesty: FedRAMP authorization, hash-chain audit immutability, and native SIEM connectors are documented gaps. Your assessor validates control design and operating effectiveness in your environment and system boundary.

Engage security@trustholm.com during trial for control mapping workshops scoped to your deployment. Use this page as evidence framing-not proof of vendor certification.

TopicEvidenceStatusNotes
PR.AC identity managementPortal users/roles, JWT sessions, MFA, SSO callbacksShipped-
PR.DS data securitySchema-per-tenant PostgreSQL; tenant-bound API accessShipped-
DE.AE security monitoringSecurity audit export JSON/CSV; Event Hub/DCR sink; HTTP logs with tenant enrichmentShippedSplunk/Datadog native sink templates remain backlog
Vendor NIST 800-53 moderate baselineConsumer maps controls in SSP; we supply artifact tablesPartial-
FedRAMP authorizationNot claimedGap-

Frequently asked questions

Does Trustholm hold FedRAMP authorization?

No. We provide evidence artifacts for customer assessments. FedRAMP authorization is not claimed on marketing pages.

Which NIST CSF functions map best?

Most directly: Protect (access control, data security) and Detect (audit export, monitoring hooks). Exact mapping depends on your system boundary.

Can we use audit export for 800-53 AU controls?

Yes-security audit export supports assessor review. Pair with your log retention and review procedures documented in the SSP.

Does Trustholm replace our SIEM?

No. JSON/CSV export ships today; native Sentinel connector is backlog. Forward exports to your SIEM with deployment-specific pipelines.

How should US MSPs cite this page?

As vendor evidence in customer vendor appendices-not as product certification. Your customer owns assessment outcomes.

What gaps should US questionnaires disclose?

FedRAMP, WORM audit immutability, native SIEM connectors, and customer-operated infrastructure monitoring outside the product.