Example resource management controls
As mentioned in Chapter 2, Effective Techniques for Preparing to Audit Cloud Environments, several frameworks can be used as guidelines for a list of applicable controls and test procedures when defining the scope of your audit. As a reference for this chapter, we’ll highlight a few example controls from the Center for Internet Security (CIS) and Cloud Security Alliance (CSA) that are relevant to resource management, tagging, change management, change history, and financial features within an enterprise cloud environment.
Center for Internet Security (CIS) benchmark controls
As a reminder, determining all applicable controls will need to be based on system architecture and integration, business risk management goals, and enterprise operational procedures:
- CIS Control 3 Sub-Control 3.7 – Establish and Maintain a Data Classification Scheme: Establish and maintain an overall data classification scheme for the enterprise...