LOG-04.1: Organizations should have a list of required security telemetry from their cloud providers, which will include multiple sources beyond just the management plane logs.
These sources should include a mixture of CSP security feeds, service logs/events and workload logs. This control objective can be automatically assessed by looking for a mixture of common security telemetry feeds, but this needs to be backed by manual assessment because, in many cases, security telemetry will be collected using third-party tooling (especially for workload logs).
Control automation: Both
AWS control specification: Check that more than three of the following security sources are enabled in >50% of monitored accounts:
S3 data events
Lambda data events
Security Hub
Access Analyzer
VPC Flow Logs
Config
Security Lake
AWS WAF Logs
Azure control specification: Check that more than three of the following security sources are enabled in >50% of monitored subscriptions:
Azure Defender for Cloud CSPM
AAD sign in logs
AAD activity log
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Both
AWS control specification: Check that more than three of the following security sources are enabled in >50% of monitored accounts:
S3 data events
Lambda data events
Security Hub
Access Analyzer
VPC Flow Logs
Config
Security Lake
AWS WAF Logs
Azure control specification: Check that more than three of the following security sources are enabled in >50% of monitored subscriptions:
Azure Defender for Cloud CSPM
AAD sign in logs
AAD activity log
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none