IR-05.1: Certain clear incidents are consistently and automatically remediated to reduce responder overhead. For example, if port 22 is exposed to the internet, and not blocked with a preventive control, it is autoremediated. For maturity Level 5, this capability must be consistently available at scale, managed centrally, support different rules for different environments (e.g., dev vs. prod), provide feedback to the deployment owner/team, and support approved exemptions.
  • Control automation: Either
  • AWS control specification: Config Rules for security are deployed and perform remediations
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP tool includes this capability and at least three automations are enabled

Description

  • Control automation: Either
  • AWS control specification: Config Rules for security are deployed and perform remediations
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP tool includes this capability and at least three automations are enabled