IR-03.2: It is not possible to effectively investigate many cloud incidents without access to the deployment to evaluate the context and configuration of the resources. Responders can't perform proper analysis using log files and events alone.
Responders should have, at a minimum, the capability to escalate to full read access. In many providers a "Security" or "Security Audit" default role does not provide sufficient access. Use of this role can and should be tightly controlled and use a privilege escalation or "break glass" process.
Control automation: Either
AWS control specification: * A full-read IAM role exists in the account
That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Either
AWS control specification: * A full-read IAM role exists in the account
That role is designated for incident responders (can check automatically by using a consistent role name that is the basis for the automated check)
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none