APP-04.3: CSPM or other automation tooling looks for application security-related controls and misconfigurations. These include, for example, use of cloud WAF, ensuring no workloads are directly reachable from the internet, that API gateways implement authentication/authorization, container management API endpoints are not internet-facing, cloud-hosted databases are only on private subnets or accessible through service endpoints, and similar assessments. These checks are highly correlated with application security but have usefulness in other categories such as workload and data security.
  • Control automation: Automated
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tooling enabled and monitors for application security misconfigurations and tooling

Description

  • Control automation: Automated
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tooling enabled and monitors for application security misconfigurations and tooling