RSK-05.2: Security assesses the risks of cloud providers and services within those providers on a continuous basis. Services are then approved or denied for different data types/classifications (e.g., PII).
For a maturity of Level 5, this is performed continuously as the cloud provider updates existing services and releases new services. For example, new features and services are assessed weekly for new risks or concerns.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none