RSK-05.1: The organization has a formalized process and established criteria for security to assess the risk of cloud deployments (applications/stacks) before implementation. Security is engaged both early in the process and before a provider or deployment is authorized for production. Risk assessments are also updated on a time (e.g., annual) basis or on major changes in the application or the deployment environment/provider. Remediation plans are documented for identified risks (that require remediation). To meet the requirements for maturity Level 5, there is formal documentation of these processes, templating for assessments and tracking for remediation of identified issues. All of which are ideally managed using a workflow or other automation tool.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none