GOV-03.2: An initial set of benchmarks for at least one primary IaaS/PaaS provider is established. Popular choices are the CIS Foundations Benchmark for that provider or the CSP's Best Practices controls. This control objective can be automatically assessed and enforced when using a cloud provider's automated assessment capabilities or a CSPM/CNAPP tool. The objective is manual when the benchmark is adopted but manually managed/assessed.
  • Control automation: Either
  • AWS control specification: Security Hub Security Standards enabled
  • Azure control specification: Defender for Cloud enabled
  • GCP control specification: Security Command Center enabled
  • Third-party (CSPM/CNAPP) control specification: The CSPM assessing maturity also assesses to the CIS or equivalent provider-specific practices framework for each deployment

Description

  • Control automation: Either
  • AWS control specification: Security Hub Security Standards enabled
  • Azure control specification: Defender for Cloud enabled
  • GCP control specification: Security Command Center enabled
  • Third-party (CSPM/CNAPP) control specification: The CSPM assessing maturity also assesses to the CIS or equivalent provider-specific practices framework for each deployment