RSK-04.2: Security performs documented risk assessments of all production cloud deployments. This is a consistent process, with proactive engagement with development/cloud teams. Assessments should be performed annually or on major updates to the deployment/applications architecture.
The assessments use risk and threat models that are designed for cloud and include cloud-native risks, such as credential exposure and management plane abuse.
While automated tooling can feed into a risk assessment, this requirement cannot typically be met with tools alone, because those can't automatically understand business risks.
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: This control can be automatable if the tool includes process automation for integrating business risk assessments with the identified technical risks
Description
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: This control can be automatable if the tool includes process automation for integrating business risk assessments with the identified technical risks