CA-04.2: Preventive guardrails block actions that could cause noncompliance in the cloud provider. For example, using a cloud service provider policy that blocks use of regions or services that are noncompliant for a given regulation/requirement.
Control automation: Either
AWS control specification: * An SCP for the account exists and denies certain regions
An SCP for the account exists and denies more than three services
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Either
AWS control specification: * An SCP for the account exists and denies certain regions
An SCP for the account exists and denies more than three services
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none