ORM-04.2: CSP preventive policies (AWS Service Control Policies, Azure Policies with deny rules, GCP policies) are in use and applied at the root of the hierarchy and to all individual OUs/MGs/folders.
  • Control automation: Automated
  • AWS control specification: At least one SCP is applied at the org root. At least one additional SCP is applied to every OU or non-OU account
  • Azure control specification: At least one policy with deny statements is applied at the root management group. At least one other policy with deny statements is applied to all other MGs
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: At least one SCP is applied at the org root. At least one additional SCP is applied to every OU or non-OU account
  • Azure control specification: At least one policy with deny statements is applied at the root management group. At least one other policy with deny statements is applied to all other MGs
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none