Access control
Least privilege, separation of duties, remote access.
Blackfyre maps multi-cloud and on-prem findings to the NIST SP 800-53 Rev 5 controls across all 20 families — with weighted scoring and tamper-evident evidence to support your ATO or FedRAMP process. Open source, self-host free.
Coverage · illustrative
298
NIST 800-53 controls
9
Frameworks
3 + on-prem
Clouds
Free
Apache-2.0
US federal security & privacy control catalog across 20 control families (AC, AU, SC, SI, etc.).
Least privilege, separation of duties, remote access.
Security, privacy, and role-based training.
Event logging, review, and log protection.
Control assessments, ATO, and continuous monitoring.
Baselines, change control, and least functionality.
Backup, recovery, and continuity of operations.
User / device identity, MFA, and authenticators.
Handling, reporting, and response testing.
Controlled system maintenance and tooling.
Media access, marking, storage, and sanitisation.
Facility access and environmental controls.
Security / privacy plans and rules of behaviour.
Organisation-wide security and privacy program.
Screening, termination, and transfer controls.
Consent, purpose, and privacy notices.
Categorisation, vulnerability scanning, and risk analysis.
SDLC, supplier, and developer security.
Boundary defence, cryptography, and isolation.
Flaw remediation, malware defence, and monitoring.
Supply-chain controls and component provenance.
Blackfyre maps findings to the 298 NIST 800-53 controls it tracks · one of 9 frameworks in the platform.
The same pipeline that scores your NIST 800-53 posture also produces the artifacts an auditor asks for — no spreadsheet reconciliation. Blackfyre assesses and evidences posture; it never claims a certification on your behalf.
01 · Scan
55 auditors enumerate real resources across AWS, Azure, GCP and on-prem — plus Prowler and Checkov / Semgrep / Bandit as containerised scanners.
02 · Map
Every finding maps to the 298 NIST 800-53 controls it affects. A single misconfiguration can touch several controls at once — the mapping records each one.
03 · Score
Weighted per-framework scoring rolls findings into a posture score you track as your team ships fixes — no spreadsheet reconciliation.
04 · Evidence
Each result is written to a tamper-evident vault — SHA-256 integrity hash, S3 Object Lock, versioning — ready to hand to an auditor.
Illustrative vault record · shows the shape, not real data
55
Auditors
298
NIST 800-53 controls
3 + on-prem
Clouds
SHA-256
Tamper-evident
Blackfyre is Apache-2.0 — self-host it free forever, or try the hosted option (early access). First findings and mapped NIST 800-53 evidence in about fifteen minutes locally. It assesses and evidences your posture; it does not certify compliance.
298
NIST 800-53 controls
9
Frameworks
55
Auditors
Free
Apache-2.0