WKL-03.3: Instances/VMs should not run in the cloud for extended periods of time. This often correlates with more-vulnerable resources because it can indicate unpatched systems even without the use of a vulnerability scan. Many of these workloads have been forgotten or abandoned but still represent a gateway for attackers.
  • Control automation: Automated
  • AWS control specification: * Instances have a launch data >1 year
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: * Instances have a launch data >1 year
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none