ORM-02.2: A checklist of core security controls is used for new deployments and may be used to evaluate existing deployments. This may not be as complete as the benchmarks used in GOV-03.2 and is considered to meet this maturity level if it is documented and manually checked, with an artifact of the results saved.
This control objective can be automatically validated when using a CSPM/CNAPP or CSP-equivalent tool and the results show 70% or better compliance with default configuration recommendations.
Control automation: Either
AWS control specification: Security Hub enabled with 70% or better compliance with AWS Security Best Practices
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Account is onboarded to CSPM and >70% compliant with critical and high policies
Description
Control automation: Either
AWS control specification: Security Hub enabled with 70% or better compliance with AWS Security Best Practices
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Account is onboarded to CSPM and >70% compliant with critical and high policies