LOG-04.1: Organizations should have a list of required security telemetry from their cloud providers, which will include multiple sources beyond just the management plane logs. These sources should include a mixture of CSP security feeds, service logs/events and workload logs. This control objective can be automatically assessed by looking for a mixture of common security telemetry feeds, but this needs to be backed by manual assessment because, in many cases, security telemetry will be collected using third-party tooling (especially for workload logs).
  • Control automation: Both
  • AWS control specification: Check that more than three of the following security sources are enabled in >50% of monitored accounts:
  • S3 data events
  • Lambda data events
  • Security Hub
  • Access Analyzer
  • VPC Flow Logs
  • Config
  • Security Lake
  • AWS WAF Logs
  • Azure control specification: Check that more than three of the following security sources are enabled in >50% of monitored subscriptions:
  • Azure Defender for Cloud CSPM
  • AAD sign in logs
  • AAD activity log
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Both
  • AWS control specification: Check that more than three of the following security sources are enabled in >50% of monitored accounts:
  • S3 data events
  • Lambda data events
  • Security Hub
  • Access Analyzer
  • VPC Flow Logs
  • Config
  • Security Lake
  • AWS WAF Logs
  • Azure control specification: Check that more than three of the following security sources are enabled in >50% of monitored subscriptions:
  • Azure Defender for Cloud CSPM
  • AAD sign in logs
  • AAD activity log
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none