LOG-03.2: All cloud providers include add-on security feeds that often require separate subscriptions. While these can incrementally increase costs, they can typically perform monitoring and alerting for active cloud threats that are difficult to otherwise obtain and build.
These feeds should be enabled for at least production deployments, with the results feeding a SIEM or other monitoring platform.
Control automation: Automated
AWS control specification: GuardDuty (GD) is enabled in at least two regions in all accounts labeled "production." If accounts are not labeled, pass if 50% of accounts use GD
Azure control specification: Defender for Cloud Standard is enabled in all subscriptions labeled production. If subscriptions are not labeled, pass if >50% of subscriptions use Defender
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: GuardDuty (GD) is enabled in at least two regions in all accounts labeled "production." If accounts are not labeled, pass if 50% of accounts use GD
Azure control specification: Defender for Cloud Standard is enabled in all subscriptions labeled production. If subscriptions are not labeled, pass if >50% of subscriptions use Defender
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none