LOG-03.2: All cloud providers include add-on security feeds that often require separate subscriptions. While these can incrementally increase costs, they can typically perform monitoring and alerting for active cloud threats that are difficult to otherwise obtain and build. These feeds should be enabled for at least production deployments, with the results feeding a SIEM or other monitoring platform.
  • Control automation: Automated
  • AWS control specification: GuardDuty (GD) is enabled in at least two regions in all accounts labeled "production." If accounts are not labeled, pass if 50% of accounts use GD
  • Azure control specification: Defender for Cloud Standard is enabled in all subscriptions labeled production. If subscriptions are not labeled, pass if >50% of subscriptions use Defender
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: GuardDuty (GD) is enabled in at least two regions in all accounts labeled "production." If accounts are not labeled, pass if 50% of accounts use GD
  • Azure control specification: Defender for Cloud Standard is enabled in all subscriptions labeled production. If subscriptions are not labeled, pass if >50% of subscriptions use Defender
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none