RSK-05.2: Security assesses the risks of cloud providers and services within those providers on a continuous basis. Services are then approved or denied for different data types/classifications (e.g., PII). For a maturity of Level 5, this is performed continuously as the cloud provider updates existing services and releases new services. For example, new features and services are assessed weekly for new risks or concerns.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none