GOV-03.3: A centralized registry of approved cloud providers and deployments is maintained. This includes, at a minimum, the deployment ID, the deployment owner and a risk or classification rating. Additional recommended fields include a technical contact, the CSP support level, a CSP contact (like an account manager), the type of deployment (e.g., dev vs. prod), any required regulatory compliance and data sensitivity/classification (e.g., PII). The registry can be a spreadsheet, database or similar. Generally, CSPM/CNAPP tools do NOT meet this objective because they are unable to cover both SaaS and IaaS/PaaS.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none