DAT-02.1: Object storage (e.g., S3, Blob storage) is not public unless approved. This is one of the most common sources of cloud data exposure; often due to accidental misconfigurations. For maturity Level 2, this does not need to be fully automated, and controls may be manually managed because all cloud providers default to private storage.
  • Control automation: Automated
  • AWS control specification: S3 buckets are not public. Individual buckets that are approved can be exempted
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: S3 buckets are not public. Individual buckets that are approved can be exempted
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none