CA-04.1: Although compliance for cloud deployments includes more than just technical configurations, the configuration state is continuously monitored using automated tools. These are typically CSPM/CNAPP tools but may also include compliance automation tools with cloud integrations.
For maturity Level 4, the tools in use must cover all major compliance standards the organization must comply with and provide standards-specific reports. For example, a report on PCI or HIPAA and not a generic framework like NIST 800-53 of CIS Foundations Benchmark, unless that framework is designated and accepted by the regulator/compliance body as fully meeting the requirements.
Control automation: Partially Automated
AWS control specification: * Security Hub is in use with Security Standards and the organization attests that this meets their compliance requirements for that account
OR
AWS Audit manager is in use and the organization attests that this meets their compliance requirements
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: The CSPM/CNAPP supports the compliance frameworks required by the customer and provides supporting artifacts for audits
Description
Control automation: Partially Automated
AWS control specification: * Security Hub is in use with Security Standards and the organization attests that this meets their compliance requirements for that account
OR
AWS Audit manager is in use and the organization attests that this meets their compliance requirements
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: The CSPM/CNAPP supports the compliance frameworks required by the customer and provides supporting artifacts for audits