APP-04.3: CSPM or other automation tooling looks for application security-related controls and misconfigurations. These include, for example, use of cloud WAF, ensuring no workloads are directly reachable from the internet, that API gateways implement authentication/authorization, container management API endpoints are not internet-facing, cloud-hosted databases are only on private subnets or accessible through service endpoints, and similar assessments.
These checks are highly correlated with application security but have usefulness in other categories such as workload and data security.
Control automation: Automated
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tooling enabled and monitors for application security misconfigurations and tooling
Description
Control automation: Automated
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tooling enabled and monitors for application security misconfigurations and tooling