> ## Documentation Index
> Fetch the complete documentation index at: https://bloodhound.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# BloodHound Enterprise Compliance Framework Resource

> BloodHound Enterprise aids numerous organizations in meeting their compliance requirements through our continuous monitoring of identity Attack Path exposure within their environments. We're eager to support you and your auditors in gaining a deeper understanding of the inner workings of BloodHound Enterprise and how we can help you meet your compliance goals.

Below, you'll find tables outlining various standard controls, detailing how BloodHound Enterprise supports these controls, and mapping them to relevant sections within the specific compliance frameworks.

Within each table, the specific controls can be expanded to learn how BloodHound Enterprise satisfies each particular control.

## Asset Management

|                                                                                                                                                                 |                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                  |                                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                               |   |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| **Control Category/Activity**                                                                                                                                   | **How Does BloodHound Enterprise Satisfy This Control?**                                                                                  | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                                                                                                           | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**                                                                                                                                                                           | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                              | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                                                                                                                                                                                                                                               |   |
| Asset Management<br /><br />The organization retains control over a system of devices, which undergoes reconciliation at intervals defined by the organization. | BloodHound Enterprise provides a comprehensive inventory of Active Directory and Azure assets through automated scans of the environment. | [ID.AM-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.AM-1)<br /><br />[ID.AM-2](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.AM-2)<br /><br />[ID.AM-5](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.AM-5)<br /><br />[PR.IP-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#PR.IP-1) | [ID.AM-01](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.AM-01)<br /><br />[ID.AM-02](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.AM-02)<br /><br />[ID.AM-05](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.AM-05) | [3.1.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.1.1)<br /><br />[3.4.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.4.1) | [CM-8](/manage-bloodhound/compliance-framework/nist-sp-800-53#CM-8-Information-System-Component-Inventory)<br /><br />[CP-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#CP-2-Contingency-Plan)<br /><br />[PM-5](/manage-bloodhound/compliance-framework/nist-sp-800-53#PM-5-Information-System-Inventory)<br /><br />[RA-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#RA-2-Security-Categorization) |   |

## Risk Assessment

|                                                                                                                                             |                                                                                             |                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |   |
| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| **Control Category/Activity**                                                                                                               | **How Does BloodHound Enterprise Satisfy This Control?**                                    | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                       | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**                                                                                                                                                                           | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |   |
| Risk Assessment<br /><br />The organization employs mechanisms to understand the cybersecurity risk to operations, assets, and individuals. | BloodHound Enterprise's attack path analysis and risk scoring help to satisfy this control. | [ID.RA-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.RA-1)<br /><br />[ID.RA-3](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.RA-3)<br /><br />[ID.RA-5](/manage-bloodhound/compliance-framework/nist-csf-v1-1#ID.RA-5) | [ID.RA-01](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.RA-01)<br /><br />[ID.RA-03](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.RA-03)<br /><br />[ID.RA-05](/manage-bloodhound/compliance-framework/nist-csf-v2#ID.RA-05) | [3.11.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.11.1)<br /><br />[3.11.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.11.2)<br /><br />[3.11.3](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.11.3)<br /><br />[3.12.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.12.1)<br /><br />[3.12.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.12.1)<br /><br />[3.12.3](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.12.3)<br /><br />[3.14.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.14.1)<br /><br />[3.14.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.14.2) | [CA-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#CA-2---Security-Assessments)<br /><br />[CA-7](/manage-bloodhound/compliance-framework/nist-sp-800-53#CA-7---Continuous-Monitoring)<br /><br />[CA-8](/manage-bloodhound/compliance-framework/nist-sp-800-53#CA-8-Penetration-Testing)<br /><br />[RA-3](/manage-bloodhound/compliance-framework/nist-sp-800-53#RA-3-Risk-Assessment)<br /><br />[RA-5](/manage-bloodhound/compliance-framework/nist-sp-800-53#RA-5-Vulnerability-Scanning)<br /><br />[SA-5](/manage-bloodhound/compliance-framework/nist-sp-800-53#SA-5-Information-System-Documentation)<br /><br />[SA-11](/manage-bloodhound/compliance-framework/nist-sp-800-53#SA-11-Security-Testing-and-Evaluation)<br /><br />[SI-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#SI-2-Flaw-Remediation)<br /><br />[SI-4](/manage-bloodhound/compliance-framework/nist-sp-800-53#SI-4-Information-Systems-Monitoring) |   |

## Configuration Management

|                                                                                                                                                                     |                                                                                                                                                |                                                                                                                                                                                                                                                  |                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | - |
| **Control Category/Activity**                                                                                                                                       | **How Does BloodHound Enterprise Satisfy This Control?**                                                                                       | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                       | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**   | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |   |
| Configuration Management<br /><br />The organization employs proactive mechanisms to detect deviations from baseline configurations within production environments. | Analysis of Active Directory/Azure Identities audits user and object permissions for deviations from established access and identity baselines | [PR.AC-4](/manage-bloodhound/compliance-framework/nist-csf-v1-1#PR.AC-4)<br /><br />[PR.IP-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#PR.IP-1)<br /><br />[DE.AE-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.AE-1) | [PR.PS-01](/manage-bloodhound/compliance-framework/nist-csf-v2#PR.PS-01) | [3.1.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.12.3)<br /><br />[3.1.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.1.2)<br /><br />[3.1.5](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.1.2)<br /><br />[3.1.6](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.1.6)<br /><br />[3.1.7](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.1.7)<br /><br />[3.4.5](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.4.5)<br /><br />[3.4.6](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.4.6) | [AC-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#AC-2----Account-Management)<br /><br />[AC-3](/manage-bloodhound/compliance-framework/nist-sp-800-53#AC-3---Access-Enforcement)<br /><br />[IA-1](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-1-Identification-and-Authentication)<br /><br />[IA-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-2-Identification-and-Authentication-\(Organizational-Users\))<br /><br />[IA-4](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-4-Identifier-Management)<br /><br />[IA-8](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-8-Identification-and-Authentication) |   |

## Detection

|   |   |   |   |   |   |   |
| - | - | - | - | - | - | - |

|                                                                                                                                     |                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                            |                                                                                                                                                                                                                        |   |
| ----------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| **Control Category/Activity**                                                                                                       | **How Does BloodHound Enterprise Satisfy This Control?**                                                                              | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                                                                                                                                                                                               | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**                                                                                                                                                                           | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                                                                                                                | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                                        |   |
| **Control Category/Activity**                                                                                                       | **How Does BloodHound Enterprise Satisfy This Control?**                                                                              | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                                                                                                                                                                                               | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**                                                                                                                                                                           | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                                                                                                                | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                                        |   |
| Detection<br /><br />The organization employs mechanisms within the environment that continuously monitor for anomalies and events. | Identity Attack Path vectors are assigned a severity rating in BloodHound Enterprise when detected during routine and on-demand scans | [DE.AE-2](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.AE-2)<br /><br />[DE.AE-4](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.AE-4)<br /><br />[DE.AE-5](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.AE-5)<br /><br />[DE.CM-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.CM-1)<br /><br />[DE.CM-8](/manage-bloodhound/compliance-framework/nist-csf-v1-1#DE.CM-8) | [DE.AE-02](/manage-bloodhound/compliance-framework/nist-csf-v2#DE.AE-02)<br /><br />[DE.AE-04](/manage-bloodhound/compliance-framework/nist-csf-v2#DE.AE-04)<br /><br />[DE.AE-08](/manage-bloodhound/compliance-framework/nist-csf-v2#DE.AE-08) | [3.3.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.4.6)<br /><br />[3.3.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.4.6)<br /><br />[3.3.5](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.5) | [CA-3](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-8-Identification-and-Authentication)<br /><br />[CM-2](/manage-bloodhound/compliance-framework/nist-sp-800-53#IA-8-Identification-and-Authentication) |   |

## Respond

|                                                                                                                                                                                |                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                  |                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                |   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| **Control Category/Activity**                                                                                                                                                  | **How Does BloodHound Enterprise Satisfy This Control?**                                                                                                                                                                                              | **[NIST CSF v1.1](/manage-bloodhound/compliance-framework/nist-csf-v1-1)**                                                                                                                                                                       | **[NIST CSF v2](/manage-bloodhound/compliance-framework/nist-csf-v2)**   | **[NIST 800-171](/manage-bloodhound/compliance-framework/nist-sp-800-171)**                                                                                                                                                                                                                                                                                                                                    | **[NIST 800-53 rev 8](/manage-bloodhound/compliance-framework/nist-sp-800-53)**                                                                                                                |   |
| Respond<br /><br />Activities are performed to ensure effective response, support recovery activities, and mitigating steps are taken to prevent the expansion of an incident. | BloodHound Enterprise detects and reports identified attack paths with a quantifiable risk metric and inventory of all impacted systems. Relevant remediation and mitigation documentation provided during analysis may help to satisfy this control. | [RS.AN-1](/manage-bloodhound/compliance-framework/nist-csf-v1-1#RS.AN-1)<br /><br />[RS.AN-2](/manage-bloodhound/compliance-framework/nist-csf-v1-1#RS.AN-2)<br /><br />[RS.MI-2](/manage-bloodhound/compliance-framework/nist-csf-v1-1#RS.MI-2) | [RS.MI-02](/manage-bloodhound/compliance-framework/nist-csf-v2#RS.AN-03) | [3.3.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.1)<br /><br />[3.3.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.1)<br /><br />[3.3.5](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.5)<br /><br />[3.6.1](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.5)<br /><br />[3.6.2](/manage-bloodhound/compliance-framework/nist-sp-800-171#3.3.5) | [CA-7](/manage-bloodhound/compliance-framework/nist-sp-800-53#CA-7---Continuous-Monitoring)<br /><br />[IR-5](/manage-bloodhound/compliance-framework/nist-sp-800-53#IR-5-Incident-Monitoring) |   |
