LOG-04.2: Cloud-native threat detectors monitor management plane and other sources for signs of cloud attacks. These are different than traditional threat detectors because they look for cloud platform activity—not necessarily network or workload activity—to indicate potential attacks. For this control objective, threat detectors beyond those built into the cloud platform's built-in threat monitoring service should be enabled (e.g., custom detectors, not just GuardDuty or Defender). These detectors can be implemented natively in the cloud platform, but will typically be run from an external SIEM or cloud detection and response (CDR) platform. Thus, this detector is difficult to automatically assess, unless the assessment tool itself includes the capability.
  • Control automation: Either
  • AWS control specification: Not effectively automatable in AWS
  • Azure control specification: Sentinel is running with default detectors (behavioral analytics) running
  • GCP control specification: Chronicle enabled with built-in detectors running
  • Third-party (CSPM/CNAPP) control specification: CSPM tool includes CDR capabilities with integrated threat detectors

Description

  • Control automation: Either
  • AWS control specification: Not effectively automatable in AWS
  • Azure control specification: Sentinel is running with default detectors (behavioral analytics) running
  • GCP control specification: Chronicle enabled with built-in detectors running
  • Third-party (CSPM/CNAPP) control specification: CSPM tool includes CDR capabilities with integrated threat detectors