CA-04.2: Preventive guardrails block actions that could cause noncompliance in the cloud provider. For example, using a cloud service provider policy that blocks use of regions or services that are noncompliant for a given regulation/requirement.
  • Control automation: Either
  • AWS control specification: * An SCP for the account exists and denies certain regions
  • An SCP for the account exists and denies more than three services
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Either
  • AWS control specification: * An SCP for the account exists and denies certain regions
  • An SCP for the account exists and denies more than three services
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none