DAT-04.1: CSP or CSPM tooling automatically and consistently scans for new public exposure of resources or data services. This includes object storage, PaaS or other databases, message queues, notification services, etc.
Control automation: Automated
AWS control specification: Use of Config Rules or Security Hub to monitor for public exposures
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM scans for any new public data repositories/services
Description
Control automation: Automated
AWS control specification: Use of Config Rules or Security Hub to monitor for public exposures
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM scans for any new public data repositories/services