ORM-03.1: A cloud security posture management tool is used to monitor for misconfigurations in cloud deployments. This control can be automated by either detecting another CSPM is in use or when the CSPM itself is performing the control assessment.
  • Control automation: Automated
  • AWS control specification: Pass if Security Hub is in use at the org level with Security Standards enabled
  • Azure control specification: Pass if Defender for Cloud is in use at the tenant level with Security Standards enabled
  • GCP control specification: Pass if Security Command Center is in use at the org level with Security Standards enabled
  • Third-party (CSPM/CNAPP) control specification: Self pass if CSPM is being used to perform the assessment

Description

  • Control automation: Automated
  • AWS control specification: Pass if Security Hub is in use at the org level with Security Standards enabled
  • Azure control specification: Pass if Defender for Cloud is in use at the tenant level with Security Standards enabled
  • GCP control specification: Pass if Security Command Center is in use at the org level with Security Standards enabled
  • Third-party (CSPM/CNAPP) control specification: Self pass if CSPM is being used to perform the assessment