RSK-02.1: A security or risk team performs a risk assessment on new cloud providers before they are authorized for use. A registry is maintained of approved providers. At this level, the risk assessment process may still be somewhat ad hoc, but it must be documented.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none