DAT-03.1: Cloud providers offer broad settings to prevent the public exposure of object storage that can be applied on a per-deployment (account/subscription/project) basis. These will ensure inadvertent or deliberate exposures and data exfiltration through object storage are prevented as the default. For example, AWS has Block Public Access and Azure allows disabling of anonymous public read for storage accounts. There are legitimate uses for public object storage, and these deployments should be exempted.
  • Control automation: Automated
  • AWS control specification: Block public access is enabled for the account (or the account is exempted)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: Block public access is enabled for the account (or the account is exempted)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none