APP-05.1: Production applications should be tested by a red team and/or penetration testing team on at least an annual basis using cloud-native techniques in combination with traditional attacks. Examples of cloud-native techniques include looking for exposed cloud credentials, attacking CI/CD pipelines, and attempting to phish and harvest access from developers/administrators. They also include enumerating public-facing resources and attempting to exploit and pivot to the cloud management plane.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none