LOG-05.1: All security telemetry across the organization is consistently and automatically deployed across the entire cloud footprint. This may take more effort than just IaC because it should include workloads, services, resources and more than the basic set of cloud management plane security feeds.
Aspects of this control objective can be automatically assessed, but this must be validated manually because, at this level, most organizations will be using extensive third-party tooling and custom configurations.
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM tooling may be able to validate that expected feeds are provisioned, depending on the technologies in use
Description
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CSPM tooling may be able to validate that expected feeds are provisioned, depending on the technologies in use