WKL-04.4: Cloud-native vulnerability assessment includes offline (snapshot/image) scanning or other techniques that are consistently effective with cloud workloads.
  • Control automation: Either
  • AWS control specification: AWS Inspector is enabled for the account (if instances are detected in the account)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tool includes offline vulnerability scanning.

Description

  • Control automation: Either
  • AWS control specification: AWS Inspector is enabled for the account (if instances are detected in the account)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CSPM or CNAPP tool includes offline vulnerability scanning.