CA-03.1: Cloud providers and services are assessed and validated as being approved for use with different regulated data types. This is on a central list and includes the specific regulations and any qualifying requirements to use the service. For example, a cloud provider's object storage might be approved for personal health information but only if encrypted using a customer-managed key. This list must specify a regulation (or contractual/internal compliance standard) and not generic data types like PII. This level of specificity is needed to properly perform and support audits. This requirement can be partially automated if the cloud provider publishes the compliance status of their services in a machine-readable format but will still require human review, approval and compilation into a list that can be distributed to development teams.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none