ORM-02.2: A checklist of core security controls is used for new deployments and may be used to evaluate existing deployments. This may not be as complete as the benchmarks used in GOV-03.2 and is considered to meet this maturity level if it is documented and manually checked, with an artifact of the results saved. This control objective can be automatically validated when using a CSPM/CNAPP or CSP-equivalent tool and the results show 70% or better compliance with default configuration recommendations.
  • Control automation: Either
  • AWS control specification: Security Hub enabled with 70% or better compliance with AWS Security Best Practices
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Account is onboarded to CSPM and >70% compliant with critical and high policies

Description

  • Control automation: Either
  • AWS control specification: Security Hub enabled with 70% or better compliance with AWS Security Best Practices
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Account is onboarded to CSPM and >70% compliant with critical and high policies