DAT-02.1: Object storage (e.g., S3, Blob storage) is not public unless approved. This is one of the most common sources of cloud data exposure; often due to accidental misconfigurations.
For maturity Level 2, this does not need to be fully automated, and controls may be manually managed because all cloud providers default to private storage.
Control automation: Automated
AWS control specification: S3 buckets are not public. Individual buckets that are approved can be exempted
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: S3 buckets are not public. Individual buckets that are approved can be exempted
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none