GOV-03.3: A centralized registry of approved cloud providers and deployments is maintained. This includes, at a minimum, the deployment ID, the deployment owner and a risk or classification rating. Additional recommended fields include a technical contact, the CSP support level, a CSP contact (like an account manager), the type of deployment (e.g., dev vs. prod), any required regulatory compliance and data sensitivity/classification (e.g., PII).
The registry can be a spreadsheet, database or similar. Generally, CSPM/CNAPP tools do NOT meet this objective because they are unable to cover both SaaS and IaaS/PaaS.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none