IR-03.2: It is not possible to effectively investigate many cloud incidents without access to the deployment to evaluate the context and configuration of the resources. Responders can't perform proper analysis using log files and events alone. Responders should have, at a minimum, the capability to escalate to full read access. In many providers a "Security" or "Security Audit" default role does not provide sufficient access. Use of this role can and should be tightly controlled and use a privilege escalation or "break glass" process.
  • Control automation: Either
  • AWS control specification: * A full-read IAM role exists in the account
  • That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Either
  • AWS control specification: * A full-read IAM role exists in the account
  • That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none