GOV-03.2: An initial set of benchmarks for at least one primary IaaS/PaaS provider is established. Popular choices are the CIS Foundations Benchmark for that provider or the CSP's Best Practices controls.
This control objective can be automatically assessed and enforced when using a cloud provider's automated assessment capabilities or a CSPM/CNAPP tool. The objective is manual when the benchmark is adopted but manually managed/assessed.
Control automation: Either
AWS control specification: Security Hub Security Standards enabled
Azure control specification: Defender for Cloud enabled
GCP control specification: Security Command Center enabled
Third-party (CSPM/CNAPP) control specification: The CSPM assessing maturity also assesses to the CIS or equivalent provider-specific practices framework for each deployment
Description
Control automation: Either
AWS control specification: Security Hub Security Standards enabled
Azure control specification: Defender for Cloud enabled
GCP control specification: Security Command Center enabled
Third-party (CSPM/CNAPP) control specification: The CSPM assessing maturity also assesses to the CIS or equivalent provider-specific practices framework for each deployment