DAT-04.1: CSP or CSPM tooling automatically and consistently scans for new public exposure of resources or data services. This includes object storage, PaaS or other databases, message queues, notification services, etc.
  • Control automation: Automated
  • AWS control specification: Use of Config Rules or Security Hub to monitor for public exposures
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM scans for any new public data repositories/services

Description

  • Control automation: Automated
  • AWS control specification: Use of Config Rules or Security Hub to monitor for public exposures
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM scans for any new public data repositories/services