RSK-03.1: The cloud provider registry includes which data types and classifications are approved for the provider. This aligns the risk level with the data classification instead of forcing a uniform risk tolerance across providers. Data classification can be by type, compliance requirement or general classification level, but it should be aligned with existing schemas.
Ratings should be determined during the risk assessment process and should be reviewed at least annually, after any major change to the provider, or upon request from a business unit with a need to use the provider with a different data type.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none