LOG-04.2: Cloud-native threat detectors monitor management plane and other sources for signs of cloud attacks. These are different than traditional threat detectors because they look for cloud platform activity—not necessarily network or workload activity—to indicate potential attacks.
For this control objective, threat detectors beyond those built into the cloud platform's built-in threat monitoring service should be enabled (e.g., custom detectors, not just GuardDuty or Defender). These detectors can be implemented natively in the cloud platform, but will typically be run from an external SIEM or cloud detection and response (CDR) platform. Thus, this detector is difficult to automatically assess, unless the assessment tool itself includes the capability.
Control automation: Either
AWS control specification: Not effectively automatable in AWS
Azure control specification: Sentinel is running with default detectors (behavioral analytics) running
GCP control specification: Chronicle enabled with built-in detectors running
Third-party (CSPM/CNAPP) control specification: CSPM tool includes CDR capabilities with integrated threat detectors
Description
Control automation: Either
AWS control specification: Not effectively automatable in AWS
Azure control specification: Sentinel is running with default detectors (behavioral analytics) running
GCP control specification: Chronicle enabled with built-in detectors running
Third-party (CSPM/CNAPP) control specification: CSPM tool includes CDR capabilities with integrated threat detectors