RSK-05.1: The organization has a formalized process and established criteria for security to assess the risk of cloud deployments (applications/stacks) before implementation.
Security is engaged both early in the process and before a provider or deployment is authorized for production. Risk assessments are also updated on a time (e.g., annual) basis or on major changes in the application or the deployment environment/provider. Remediation plans are documented for identified risks (that require remediation).
To meet the requirements for maturity Level 5, there is formal documentation of these processes, templating for assessments and tracking for remediation of identified issues. All of which are ideally managed using a workflow or other automation tool.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none