Frameworks
Pump Secure supports 39 compliance and security frameworks. You choose which frameworks to activate, and Pump runs the corresponding checks against your AWS environment. A single check can map to multiple frameworks, so activating additional frameworks does not necessarily increase scan time.
Browsing and Activating Frameworks
To manage your active frameworks:
Navigate to Secure in the Pump sidebar.
Click Manage next to the "Frameworks" heading at the top of the dashboard.
The framework picker opens, showing all 39 available frameworks with toggle switches.
Enable the frameworks you want to scan against, then click Save.
The AWS Well-Architected Framework is enabled by default and marked as "Recommended." You can disable it or add any combination of the other 38 frameworks.
Changes take effect on the next scan cycle. New frameworks will show results once the next scan completes.
Available Frameworks
AWS-Native Frameworks
AWS Well-Architected Framework
AWS best practices for building secure, high-performing, resilient, and efficient infrastructure. Recommended by Pump as a baseline.
AWS Account Security Onboarding
Security checks for newly created or recently connected AWS accounts.
AWS Audit Manager Control Tower Guardrails
Controls aligned with AWS Control Tower governance rules.
AWS Foundational Security Best Practices
AWS-curated set of foundational security controls.
AWS Foundational Technical Review
Checks aligned with the AWS Foundational Technical Review (FTR) for AWS Partner solutions.
CIS Controls
CIS Controls 1.4
Center for Internet Security Controls version 1.4.
CIS Controls 1.5
CIS Controls version 1.5.
CIS Controls 2.0
CIS Controls version 2.0.
CIS Controls 3.0
CIS Controls version 3.0.
CIS Controls 6.0
CIS Controls version 6.0.
NIST Frameworks
NIST 800 171 Revision 2
Protecting Controlled Unclassified Information (CUI) in nonfederal systems.
NIST 800 53 Revision 4
Security and privacy controls for federal information systems.
NIST 800 53 Revision 5
Updated security and privacy controls (current revision).
NIST CSF 1.1
NIST Cybersecurity Framework version 1.1.
NIST CSF 2.0
NIST Cybersecurity Framework version 2.0 (current).
PCI DSS
PCI 3.2.1
Payment Card Industry Data Security Standard version 3.2.1.
PCI 4.0
PCI DSS version 4.0 (current).
ISO Standards
ISO 27001 2013
Information security management systems (2013 edition).
ISO 27001 2022
Information security management systems (2022 edition, current).
FedRAMP
FedRAMP Low Revision 4
Federal Risk and Authorization Management Program, Low baseline.
FedRAMP Moderate Revision 4
FedRAMP Moderate baseline.
FedRAMP 20x Key Security Indicators (KSI) Low
FedRAMP 20x KSI Low baseline.
Healthcare and Life Sciences
HIPAA
Health Insurance Portability and Accountability Act security controls.
GxP Title 21 CFR Part 11
FDA regulations for electronic records and signatures.
GxP EU Annex 11
EU GMP Annex 11 for computerized systems in pharmaceutical manufacturing.
Financial Services
Federal Financial Institutions Examination Council (FFIEC)
IT security standards for US financial institutions.
Reserve Bank of India (RBI)
Information security guidelines for Indian financial institutions.
SOC 2
Service Organization Control 2 trust services criteria.
Government and Public Sector
Cybersecurity and Infrastructure Security Agency (CISA)
US federal cybersecurity best practices.
Esquema Nacional de Seguridad (ENS)
Spain's national security framework for public sector.
KISA ISMS-P 2023
Korea Internet & Security Agency information security management system.
KISA ISMS-P 2023 Korean
KISA ISMS-P 2023 (Korean language version).
SecNumCloud 3.2
French ANSSI cloud security qualification framework.
Cloud Security Frameworks
Cloud Computing Compliance Criteria Catalogue (C5)
German BSI cloud security standard.
Common Cloud Controls (CCC)
Cross-cloud security control framework.
CSA Cloud Controls Matrix (CCM) 4.0
Cloud Security Alliance control framework version 4.0.
Threat Intelligence
MITRE ATT&CK
Adversary tactics and techniques mapped to AWS security controls.
Data Protection
General Data Protection Regulation (GDPR)
EU data protection and privacy regulation.
Pump-Curated
Pump Pentest for AWS
A Pump-curated set of security checks focused on common AWS misconfigurations that would be flagged in a penetration test. This is a compliance-check framework, not an active penetration test.
How Frameworks Relate to Checks
Each framework consists of a set of checks. Many checks appear across multiple frameworks. For example, a check like "Ensure no security groups allow ingress from 0.0.0.0/0 to MySQL port 3306" might map to CIS Controls, AWS Well-Architected, MITRE ATT&CK, and others simultaneously.
In the findings table, the Frameworks affected column shows which of your active frameworks each check maps to. This helps you prioritize: a finding that affects five active frameworks is typically more urgent than one that affects a single framework.
Choosing Frameworks
If you are not sure which frameworks to activate, start with the AWS Well-Architected Framework (enabled by default). It provides broad coverage of AWS security best practices without being tied to a specific regulatory requirement.
Add additional frameworks based on your compliance obligations:
SOC 2 audit requirements
SOC 2
HIPAA for healthcare data
HIPAA
PCI DSS for payment processing
PCI 3.2.1 or PCI 4.0 (depending on your audit cycle)
US federal requirements
FedRAMP Low or Moderate, NIST 800 53, CISA
EU data protection
GDPR
ISO certification
ISO 27001 2022
General security hardening
CIS Controls 3.0 or 6.0, MITRE ATT&CK
Last updated
Was this helpful?

