IR-03.1: Multiple cloud playbooks are in place to define and document the response processes for major types of cloud incidents, ideally aligned with a framework like MITRE ATT&CK. Some examples for playbooks are: exposed credentials, suspected credential abuse, cryptomining and unexpected public data disclosure (e.g., public S3/blob/cloud file).
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none