APP-02.1: Threat modeling is performed on applications built or migrated to the cloud. The threat modeling accounts for the different risks in cloud, but includes at least the following elements: * Assessment of the risks of public-facing resources * Inclusion of IAM risks; especially, the risks of static credentials
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none