IR-05.1: Certain clear incidents are consistently and automatically remediated to reduce responder overhead. For example, if port 22 is exposed to the internet, and not blocked with a preventive control, it is autoremediated.
For maturity Level 5, this capability must be consistently available at scale, managed centrally, support different rules for different environments (e.g., dev vs. prod), provide feedback to the deployment owner/team, and support approved exemptions.
Control automation: Either
AWS control specification: Config Rules for security are deployed and perform remediations
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP tool includes this capability and at least three automations are enabled
Description
Control automation: Either
AWS control specification: Config Rules for security are deployed and perform remediations
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM/CNAPP tool includes this capability and at least three automations are enabled