ORM-04.2: CSP preventive policies (AWS Service Control Policies, Azure Policies with deny rules, GCP policies) are in use and applied at the root of the hierarchy and to all individual OUs/MGs/folders.
Control automation: Automated
AWS control specification: At least one SCP is applied at the org root. At least one additional SCP is applied to every OU or non-OU account
Azure control specification: At least one policy with deny statements is applied at the root management group. At least one other policy with deny statements is applied to all other MGs
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: At least one SCP is applied at the org root. At least one additional SCP is applied to every OU or non-OU account
Azure control specification: At least one policy with deny statements is applied at the root management group. At least one other policy with deny statements is applied to all other MGs
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none