WKL-02.2: Instances/VMs are consistently assessed for vulnerabilities, but not necessarily with cloud native tooling. This can be automatically assessed when using CSP vulnerability assessment services, but will need to be manually validated when using other options, such as an existing vulnerability assessment platform or service.
  • Control automation: Either
  • AWS control specification: AWS Inspector is enabled for the account (if instances are detected in the account)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the tooling includes endpoint scanning (e.g., snapshot or image scanning)

Description

  • Control automation: Either
  • AWS control specification: AWS Inspector is enabled for the account (if instances are detected in the account)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the tooling includes endpoint scanning (e.g., snapshot or image scanning)