RSK-03.1: The cloud provider registry includes which data types and classifications are approved for the provider. This aligns the risk level with the data classification instead of forcing a uniform risk tolerance across providers. Data classification can be by type, compliance requirement or general classification level, but it should be aligned with existing schemas. Ratings should be determined during the risk assessment process and should be reviewed at least annually, after any major change to the provider, or upon request from a business unit with a need to use the provider with a different data type.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none