APP-05.1: Production applications should be tested by a red team and/or penetration testing team on at least an annual basis using cloud-native techniques in combination with traditional attacks. Examples of cloud-native techniques include looking for exposed cloud credentials, attacking CI/CD pipelines, and attempting to phish and harvest access from developers/administrators. They also include enumerating public-facing resources and attempting to exploit and pivot to the cloud management plane.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none