ORM-03.2: CSP preventive policies (AWS Service Control Policies, Azure Policies with deny rules, GCP policies) are in use and applied at the root of the hierarchy and to individual org units (OUs)/management groups (MGs)/folders.
Using policies at multiple levels of the hierarchy doesn't necessarily indicate all the right policies are in place, but they are a good key indicator that a strategy exists and is being implemented.
Control automation: Automated
AWS control specification: At least one SCP is applied at the org root. At least two additional SCPs are applied to two or more OUs.
Azure control specification: At least one policy with deny statements is applied at the root management group. At least two other policies with deny statements are applied to two or more other MGs.
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: At least one SCP is applied at the org root. At least two additional SCPs are applied to two or more OUs.
Azure control specification: At least one policy with deny statements is applied at the root management group. At least two other policies with deny statements are applied to two or more other MGs.
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none