Assured Workloads frameworks

This page provides reference content for the built-in frameworks that are included in Assured Workloads and Audit Manager.

Google Recommended AI Essentials - Gemini Enterprise Agent Platform

Supported cloud provider: Google Cloud

This framework outlines Google recommended security best practices for Gemini Enterprise Agent Platform workloads, providing a prescriptive collection of essential preventative and detective policies. When you acctivate AI Protection within the Security Command Center, a detailed security compliance assessment against this framework is automatically displayed on the Agent Platform Security dashboard.

This framework includes the following cloud controls:

CIS GCP Foundations Benchmark v3.0

Supported cloud provider: Google Cloud

Prescriptive guidance for establishing a secure baseline configuration for Google Cloud Platform. This benchmark provides technical best practices for hardening foundational services like IAM, Logging, Networking, and Storage.

This framework includes the following cloud controls:

CIS GKE 1.7

Supported cloud provider: Google Cloud

The CIS GKE Benchmark is a set of security recommendations and best practices specifically tailored for Google Kubernetes Engine (GKE) clusters. The benchmark aims to enhance the security posture of GKE environments.

This framework includes the following cloud controls:

CIS Critical Security Controls v8

Supported cloud provider: Google Cloud

A prioritized set of safeguards to protect against prevalent cyber threats. It offers a practical approach to cyber defense, tiered into Implementation Groups (IG1, IG2, IG3) to suit organizations of varying maturity.

This framework includes the cloud control groups and cloud controls in the following sections.

cis-controls-1-1

Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.

cis-controls-10-2

Configure automatic updates for anti-malware signature files on all enterprise assets.

cis-controls-10-3

Disable autorun and autoplay auto-execute functionality for removable media.

cis-controls-10-6

Centrally manage anti-malware software.

cis-controls-11-1

Establish and maintain a documented data recovery process that includes detailed backup procedures. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-11-2

Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.

cis-controls-11-3

Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.

cis-controls-11-4

Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.

cis-controls-11-5

Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.

cis-controls-12-2

Design and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum. Example implementations may include documentation, policy, and design components.

cis-controls-12-3

Securely manage network infrastructure. Example implementations include version-controlled Infrastructure-as-Code (IaC), and the use of secure network protocols, such as SSH and HTTPS.

cis-controls-12-5

Centralize network AAA.

cis-controls-12-6

Adopt secure network management protocols (e.g., 802.1X) and secure communication protocols (e.g., Wi-Fi Protected Access 2 (WPA2) Enterprise or more secure alternatives).

cis-controls-12-7

Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.

cis-controls-13-1

Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this Safeguard.

cis-controls-13-2

Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.

cis-controls-13-3

Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service.

cis-controls-13-4

Perform traffic filtering between network segments, where appropriate.

cis-controls-13-5

Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date.

cis-controls-13-6

Collect network traffic flow logs and/or network traffic to review and alert upon from network devices.

cis-controls-13-7

Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.

cis-controls-13-8

Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.

cis-controls-13-9

Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.

cis-controls-14-1

Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-14-3

Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.

cis-controls-14-5

Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to unintended audiences.

cis-controls-16-1

Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-16-11

Leverage vetted modules or services for application security components, such as identity management, encryption, auditing, and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern operating systems provide effective mechanisms for identification, authentication, and authorization and make those mechanisms available to applications. Use only standardized, currently accepted, and extensively reviewed encryption algorithms. Operating systems also provide mechanisms to create and maintain secure audit logs.

cis-controls-16-12

Apply static and dynamic analysis tools within the application life cycle to verify that secure coding practices are being followed.

cis-controls-16-2

Establish and maintain a process to accept and address reports of software vulnerabilities, including providing a means for external entities to report. The process is to include such items as: a vulnerability handling policy that identifies reporting process, responsible party for handling vulnerability reports, and a process for intake, assignment, remediation, and remediation testing. As part of the process, use a vulnerability tracking system that includes severity ratings and metrics for measuring timing for identification, analysis, and remediation of vulnerabilities. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard. Third-party application developers need to consider this an externally-facing policy that helps to set expectations for outside stakeholders.

cis-controls-16-3

Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.

cis-controls-16-7

Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening.

cis-controls-17-2

Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, service providers, law enforcement, cyber insurance providers, relevant government agencies, Information Sharing and Analysis Center (ISAC) partners, or other stakeholders. Verify contacts annually to ensure that information is up-to-date.

cis-controls-17-4

Establish and maintain a documented incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-17-9

Establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. Examples can include: abnormal activity, security vulnerability, security weakness, data breach, privacy incident, etc. Review annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-18-1

Establish and maintain a penetration testing program appropriate to the size, complexity, industry, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.

cis-controls-18-2

Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.

cis-controls-18-5

Perform periodic internal penetration tests based on program requirements, no less than annually. The testing may be clear box or opaque box.

cis-controls-2-7

Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1 and .py files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.

cis-controls-3-1

Establish and maintain a documented data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-3-11

Encrypt sensitive data at rest on servers, applications, and databases. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.

cis-controls-3-14

Log sensitive data access, including modification and disposal.

cis-controls-3-2

Establish and maintain a data inventory based on the enterprise’s data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.

cis-controls-3-3

Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.

cis-controls-3-4

Retain data according to the enterprise’s documented data management process. Data retention must include both minimum and maximum timelines.

cis-controls-3-5

Securely dispose of data as outlined in the enterprise’s documented data management process. Ensure the disposal process and method are commensurate with the data sensitivity.

cis-controls-3-6

Encrypt data on end-user devices containing sensitive data. Example implementations can include: Windows BitLocker®, Apple FileVault®, Linux® dm-crypt.

cis-controls-3-7

Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-3-8

Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprise’s data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-3-9

Encrypt data on removable media.

cis-controls-4-1

Establish and maintain a documented secure configuration process for enterprise assets (end-user devices, including portable and mobile, non-computing/IoT devices, and servers) and software (operating systems and applications). Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-4-2

Establish and maintain a documented secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-4-3

Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.

cis-controls-4-4

Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.

cis-controls-4-5

Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.

cis-controls-4-6

Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled Infrastructure-as-Code (IaC) and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). Do not use insecure management protocols, such as Telnet (Teletype Network) and HTTP, unless operationally essential.

cis-controls-4-7

Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.

cis-controls-4-8

Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.

cis-controls-5-1

Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must at a minimum include user, administrator, and service accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.

cis-controls-5-2

Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using Multi-Factor Authentication (MFA) and a 14-character password for accounts not using MFA. 

cis-controls-5-4

Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.

cis-controls-5-5

Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.

cis-controls-5-6

Centralize account management through a directory or identity service.

cis-controls-6-1

Establish and follow a documented process, preferably automated, for granting access to enterprise assets upon new hire or role change of a user.

cis-controls-6-2

Establish and follow a process, preferably automated, for revoking access to enterprise assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails.

cis-controls-6-3

Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.

cis-controls-6-5

Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a service provider.

cis-controls-6-6

Establish and maintain an inventory of the enterprise’s authentication and authorization systems, including those hosted on-site or at a remote service provider. Review and update the inventory, at a minimum, annually, or more frequently.

cis-controls-6-7

Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.

cis-controls-6-8

Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.

cis-controls-7-2

Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.

cis-controls-7-7

Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.

cis-controls-8-1

Establish and maintain a documented audit log management process that defines the enterprise’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

cis-controls-8-11

Conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis.

cis-controls-8-2

Collect audit logs. Ensure that logging, per the enterprise’s audit log management process, has been enabled across enterprise assets.

cis-controls-8-3

Ensure that logging destinations maintain adequate storage to comply with the enterprise’s audit log management process.

cis-controls-8-4

Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported.

cis-controls-8-5

Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.

cis-controls-8-6

Collect DNS query audit logs on enterprise assets, where appropriate and supported.

cis-controls-8-7

Collect URL request audit logs on enterprise assets, where appropriate and supported.

cis-controls-8-8

Collect command-line audit logs. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals.

cis-controls-8-9

Centralize, to the extent possible, audit log collection and retention across enterprise assets in accordance with the documented audit log management process. Example implementations primarily include leveraging a SIEM tool to centralize multiple log sources.

cis-controls-9-1

Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.

cis-controls-9-2

Use DNS filtering services on all end-user devices, including remote and on-premises assets, to block access to known malicious domains.

cis-controls-9-3

Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.

cis-controls-9-4

Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.

CSA Cloud Controls Matrix v4.0.11

Supported cloud provider: Google Cloud

A cybersecurity control framework designed specifically for the cloud computing environment. It provides a comprehensive set of controls across key domains to help you assess the security posture of your cloud services.

This framework includes the cloud control groups and cloud controls in the following sections.

ccm-aa-01

Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.

ccm-aa-02

Conduct independent audit and assurance assessments according to relevant standards at least annually.

ccm-ais-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at least annually.

ccm-ais-02

Establish, document and maintain baseline requirements for securing different applications.

ccm-ais-03

Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.

ccm-ais-04

Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.

ccm-ais-05

Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.

ccm-bcr-03

Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.

ccm-bcr-07

Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.

ccm-bcr-08

Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.

ccm-bcr-09

Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.

ccm-bcr-10

Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.

ccm-bcr-11

Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.

ccm-ccc-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc. The policies and procedures must be managed, regardless of whether the assets are managed internally or externally. Review and update the policies and procedures at least annually.

ccm-ccc-02

Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.

ccm-ccc-07

Implement detection measures with proactive notification in case of changes deviating from the established baseline.

ccm-cek-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.

ccm-cek-02

Define and implement cryptographic, encryption and key management roles and responsibilities.

ccm-cek-03

Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.

ccm-cek-04

Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.

ccm-cek-05

Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.

ccm-cek-08

CSPs must provide the capability for CSCs to manage their own data encryption keys.

ccm-cek-10

Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.

ccm-cek-11

Manage cryptographic secret and private keys that are provisioned for a unique purpose.

ccm-cek-18

Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.

ccm-cek-21

Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.

ccm-dcs-07

Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.

ccm-dcs-09

Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.

ccm-dsp-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and procedures at least annually.

ccm-dsp-02

Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.

ccm-dsp-07

Develop systems, products, and business practices based upon a principle of security by design and industry best practices.

ccm-dsp-08

Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.

ccm-dsp-10

Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.

ccm-dsp-16

Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.

ccm-dsp-17

Define and implement, processes, procedures and technical measures to protect sensitive data throughout its lifecycle.

ccm-grc-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.

ccm-grc-03

Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.

ccm-grc-07

Identify and document all relevant standards, regulations, legal, contractual, and statutory requirements, which are applicable to your organization.

ccm-iam-01

Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.

ccm-iam-03

Manage, store, and review the information of system identities, and level of access.

ccm-iam-04

Employ the separation of duties principle when implementing information system access.

ccm-iam-05

Employ the least privilege principle when implementing information system access.

ccm-iam-07

De-provision or respectively modify access of movers, leavers, or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.

ccm-iam-09

Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.

ccm-iam-10

Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.

ccm-iam-11

Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk privileged access roles as defined by the organizational risk assessment.

ccm-iam-12

Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and break glass procedures.

ccm-iam-13

Define, implement and evaluate processes, procedures and technical measures that ensure users are identifiable through unique IDs or which can associate individuals to the usage of user IDs.

ccm-iam-14

Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equivalent level of security for system identities.

ccm-iam-16

Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.

ccm-ivs-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.

ccm-ivs-03

Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.

ccm-ivs-04

Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.

ccm-ivs-06

Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.

ccm-ivs-07

Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.

ccm-ivs-09

Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.

ccm-log-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.

ccm-log-02

Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.

ccm-log-03

Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.

ccm-log-04

Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.

ccm-log-05

Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.

ccm-log-07

Establish, document and implement which information metadata and data system events should be logged. Review and update the scope at least annually or whenever there is a change in the threat environment.

ccm-log-08

Generate audit records containing relevant security information.

ccm-log-12

Monitor and log physical access using an auditable access control system.

ccm-sef-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.

ccm-sef-02

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents. Review and update the policies and procedures at least annually.

ccm-sef-08

Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.

ccm-sta-04

Delineate the shared ownership and applicability of all CSA CCM controls according to the SSRM for the cloud service offering.

ccm-sta-08

CSPs periodically review risk factors associated with all organizations within their supply chain.

ccm-sta-09

Service agreements between CSPs and CSCs (tenants) must incorporate at least the mutually-agreed upon provisions and terms that include Scope, characteristics and location of business relationship and services offered, Information security requirements (including SSRM), Change management process, Logging and monitoring capability, Incident management and communication procedures, Right to audit and third party assessment, Service termination, Interoperability and portability requirements, and Data privacy.

ccm-tvm-01

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to identify, report and prioritize the remediation of vulnerabilities, in order to protect systems against vulnerability exploitation. Review and update the policies and procedures at least annually.

ccm-tvm-02

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.

ccm-tvm-03

Define, implement and evaluate processes, procedures and technical measures to enable both scheduled and emergency responses to vulnerability identifications, based on the identified risk.

ccm-tvm-06

Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.

ccm-uem-04

Maintain an inventory of all endpoints used to store and access company data.

ccm-uem-07

Manage changes to endpoint operating systems, patch levels, and applications through the company's change management processes.

ccm-uem-10

Configure managed endpoints with properly configured software firewalls.

ccm-uem-11

Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.

DBG CSA CCM

Supported cloud provider: Google Cloud

DBG CSA CCM

This framework includes the cloud control groups and cloud controls in the following sections.

csa-ccm-bcr-08-3

The BCR-08.3 monitors configuration of standard Backup agents for three GCP services running in the current project:

The controls is violated if any of the required Backup configurations is not enabled.

csa-ccm-bcr-11-2

The BCR-11.2 monitors effective value of the Organization Policy gcp.resourceLocations.

The control is violated if the Organization Policy is not set or is not restricting location of new resources to the regions:

  • europe-west3 (Frankfurt)
  • europe-west6 (Milan)
  • europe-west8 (Zurich)

csa-ccm-bcr-11-4

The BCR-11.4 monitors geographical location of Google Cloud resources, supporting regionalization.

Complaint Google Cloud resources should be launched in any of these regions:

  • europe-west3 (Frankfurt)
  • europe-west6 (Milan)
  • europe-west8 (Zurich)

The control is violated if any other location is used. This includes EU multi-region.

csa-ccm-ccc-05-1

Check shared responsibility documentation in change procedures

csa-ccm-ccc-06

CCC-06 monitors that every Google Cloud project enables only those GCP services that have been tested and approved for usage.

csa-ccm-cek-02-5

Newly created data storage services must use CMEK, located in a specific dedicated project. This project ID must be enforced with Organization Policy constraints/gcp.restrictCmekCryptoKeyProjects

csa-ccm-cek-04-3

All keys, used for encrypting data in storage, should be generated in on-premise HSM device and then imported to GCP CMEK. All keys are stored in the cloud-based HSM system

csa-ccm-cek-08-3

All Storage Service used in GCP should use Customer Managed Encryption Key for encrypting data-at-rest.

csa-ccm-dsp-04

DSP-04.1 monitors that all resources, supporting labels, have a label attached.

csa-ccm-dsp-16

DSP-16.3 monitors configuration of GCS buckets. Every GCS bucket needs to have the Soft Delete feature enabled or both features: Object Versioning and Object Retention enabled simultaneously.

csa-ccm-ivs-05-1

IVS-05.1 monitors that every GCP project has the attached Resource Manager Tag that define the environment.

csa-ccm-ivs-09-1

Firewall rules are not using tags and do not enable access to any services from the public Internet

csa-ccm-log-04-1

Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.

csa-ccm-log-06

Use a reliable time source across all relevant information processing systems.

DORA

Supported cloud provider: Google Cloud

Digital Operational Resilience Act

This framework includes the cloud control groups and cloud controls in the following sections.

dora-article-07

Financial entities must maintain updated ICT systems, protocols and tools that are appropriate for use, reliable, and resilient.

dora-article-09

Financial entities must implement security tools that continually monitor and control ICT systems and ensure, but not limited to, privacy, availability, integrity and confidentiality.

dora-article-10

Financial entities must implement mechanisms for prompt detection of anomalous activities and support ICT related incident response.

EU Data Boundary

Supported cloud provider: Google Cloud

Supports compliance with EU data residency requirements by restricting resource locations to EU regions.

This framework includes the following cloud controls:

EU Data Boundary and Support

Supported cloud provider: Google Cloud

Supports compliance with EU data residency and support requirements by restricting resource locations to EU regions and limiting support access to EU-based personnel.

This framework includes the following cloud controls:

FedRAMP High

Supported cloud provider: Google Cloud

Controls for meeting FedRAMP High compliance requirements.

This framework includes the following cloud controls:

FedRAMP Low 20x

Supported cloud provider: Google Cloud

A Government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies. FedRAMP Low impact is most appropriate for CSOs where the loss of confidentiality, integrity and availability would result in limited adverse effect on an agency's operations, assets or individuals.

This framework includes the cloud control groups and cloud controls in the following sections.

ksi-ced-1

Ensure employees receive security awareness training.

ksi-ced-2

Mandate role-specific training for high-risk roles, in particular for roles with privileged access.

ksi-cmt-1

Log and monitor system modifications. Ensure that all system changes are documented and configuration baselines are updated.

ksi-cmt-3

Implement automated testing and validation of changes before deployment.

ksi-cmt-4

Implement a documented change management procedure.

ksi-cmt-5

Evaluate the risk and potential impact of every change.

ksi-cna-1

Configure all information resources to limit inbound and outbound traffic.

ksi-cna-2

Design systems to help reduce the attack surface and minimize lateral movement if compromised.

ksi-cna-3

Implement traffic flow controls using logical networking and related capabilities.

ksi-cna-4

Use immutable infrastructure with strictly defined functionality and privileges.

ksi-cna-5

Enforce denial-of-service protection to help protect information systems resources built on Google Cloud.

ksi-cna-6

Design information systems with high availability and rapid recovery capabilities to help prevent data loss.

ksi-cna-7

Implement cloud-first information resources that are based on the host provider's best practices and documented guidance.

ksi-iam-1

Enforce multi-factor authentication (MFA) using methods that are difficult to intercept or impersonate (phishing-resistant MFA) for user authentication.

ksi-iam-2

Implement secure, passwordless methods when feasible, or enforce strong passwords with multi-factor authentication (MFA) for secure user authentication and authorization.

ksi-iam-3

Enforce secure authentication methods for all non-user accounts and services within Google Cloud to help protect data and resources from unauthorized access.

ksi-iam-4

Implement a security authorization model that is least-privileged, role and attribute-based, and just-in-time. Use this model for all user and non-user accounts and services to help reduce the risk of unauthorized access or misuse.

ksi-iam-5

Enforce zero-trust design principles on your applications and services to enhance security.

ksi-iam-6

Automatically disable or secure accounts with privileged access when suspicious activity is detected to help mitigate security risks.

ksi-inr-1

Report incidents according to FedRAMP requirements and cloud service provider policies.

ksi-inr-2

Maintain a log of incidents and review past incidents for patterns or vulnerabilities at regular intervals.

ksi-inr-3

Generate after-action reports, and incorporate lessons learned into operations.

ksi-mla-1

Implement a centralized and tamper-resistant logging system using a Security Information and Event Management (SIEM) or similar system to record all application and service events, activities, and changes.

ksi-mla-2

Regularly review the audit logs of your applications and services.

ksi-mla-3

Detect vulnerabilities and promptly remediate or mitigate them to help reduce the risk impact on applications and services.

ksi-mla-4

Conduct regular authenticated vulnerability scans on information resources.

ksi-mla-5

Implement Infrastructure as Code (IaC) and perform configuration evaluation and testing.

ksi-mla-6

Track and prioritize the mitigation and remediation of identified vulnerabilities in a central system.

ksi-piy-1

Maintain an updated information resource inventory or code that defines all deployed assets, software, and services.

ksi-piy-2

Outline policies with the security objectives for all information resources.

ksi-piy-3

Maintain a vulnerability disclosure program that includes intentional, organized, universal guidance for how every information resource, including personnel, is secured.

ksi-piy-4

Build security considerations into the Software Development Lifecycle (SDLC) and align with Cybersecurity and Infrastructure Security Agency's (CISA's) Secure By Design principles.

ksi-piy-5

Document the methods that are used to evaluate information resource implementations.

ksi-piy-6

Maintain dedicated staff and budget for security with executive support, in line with the size, complexity, scope, and risk of the service offering.

ksi-piy-7

Document risk management decisions for software supply chain security.

ksi-rpl-1

Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) to ensure minimal service disruption and data loss during incidents and contingencies.

ksi-rpl-2

Develop and maintain a recovery plan that aligns with the defined recovery objectives.

ksi-rpl-3

Perform system backups that are aligned with recovery objectives.

ksi-rpl-4

Test your organization's ability to recover from incidents and contingencies at regular intervals.

ksi-svc-1

Regularly review and strengthen the network and system configurations to help ensure a secure baseline.

ksi-svc-2

Encrypt all core content data that is exchanged between machines that connect to Google Cloud, or alternatively, secure all network traffic to help protect data.

ksi-svc-3

Ensure all federal and sensitive information at rest is encrypted.

ksi-svc-4

Manage configurations centrally to ensure consistent governance and security.

ksi-svc-5

Implement cryptographic mechanisms and integrity verification tools to enforce system and information resource integrity and help detect unauthorized changes.

ksi-svc-6

Use automated key management systems to help protect, manage, and regularly rotate digital keys and certificates.

ksi-svc-7

Implement a consistent, risk-informed approach for applying security patches to your applications and services.

ksi-tpr-1

Identify all third-party information resources to understand, monitor, and manage supply chain risks.

ksi-tpr-2

Ensure that the services that are federal information or are likely to impact the confidentiality, integrity, or availability of federal information are FedRAMP authorized and securely configured.

ksi-tpr-3

Identify and prioritize mitigation of potential supply chain risks.

ksi-tpr-4

Monitor third-party software information resources for upstream vulnerabilities, using contractual notification requirements or active monitoring services.

FedRAMP Moderate

Supported cloud provider: Google Cloud

Controls for meeting FedRAMP Moderate compliance requirements.

This framework includes the following cloud controls:

HIPAA

Supported cloud provider: Google Cloud

Health Insurance Portability and Accountability Act

This framework includes the cloud control groups and cloud controls in the following sections.

hipaa-security-ss164-308-a-3-i-workforce-security

Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information and to prevent those workforce members who do not have access from obtaining access to electronic protected health information.

hipaa-security-ss164-308-a-3-ii-a-workforce-security-authorization-and-or-supervision

Implement procedures for the authorization and/or supervision of workforce members who work with EPHI or in locations where it might be accessed.

hipaa-security-ss164-308-a-7-ii-a-contingency-plan-data-backup-plan

Establish and implement procedures to create and maintain retrievable exact copies of EPHI.

hipaa-security-ss164-310-d-2-iii-device-and-media-controls-accountability

Maintain a record of the movements of hardware and electronic media and any person responsible therefore.

hipaa-security-ss164-312-a-1-access-control

Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights

hipaa-security-ss164-312-a-2-iv-access-control-encryption-and-decryption

Implement a mechanism to encrypt and decrypt EPHI.

hipaa-security-ss164-312-b-audit-controls

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

hipaa-security-ss164-312-e-1-transmission

Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.

hipaa-security-ss164-312-e-2-i-transmission-security-integrity-controls

Implement security measures to ensure that electronically transmitted EPHI is not improperly modified without detection until disposed of.

hipaa-security-ss164-312-e-2-ii-transmission-security-encryption

Implement a mechanism to encrypt EPHI whenever deemed appropriate.

IL2

Supported cloud provider: Google Cloud

Controls for meeting IL2 compliance requirements.

This framework includes the following cloud controls:

IL4

Supported cloud provider: Google Cloud

Controls for meeting IL4 compliance requirements.

This framework includes the following cloud controls:

IL5

Supported cloud provider: Google Cloud

Controls for meeting IL5 compliance requirements.

This framework includes the following cloud controls:

ISO 27001:2022

Supported cloud provider: Google Cloud

The international standard for an Information Security Management System (ISMS). It provides a systematic, risk-based approach to managing sensitive information by specifying requirements for establishing and improving security controls.

This framework includes the cloud control groups and cloud controls in the following sections.

iso-27001-2022-a-5-1

Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.

iso-27001-2022-a-5-10

Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented.

iso-27001-2022-a-5-12

Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.

iso-27001-2022-a-5-14

Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.

iso-27001-2022-a-5-15

Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.

iso-27001-2022-a-5-17

Allocation and management of authentication information shall be controlled by a management process, including advising personnel on appropriate handling of authentication information.

iso-27001-2022-a-5-18

Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control.

iso-27001-2022-a-5-19

Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.

iso-27001-2022-a-5-20

Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.

iso-27001-2022-a-5-23

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements.

iso-27001-2022-a-5-24

The organization shall plan and prepare for managing information security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities.

iso-27001-2022-a-5-25

The organization shall assess information security events and decide if they are to be categorized as information security incidents.

iso-27001-2022-a-5-28

The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.

iso-27001-2022-a-5-30

ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.

iso-27001-2022-a-5-33

Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release.

iso-27001-2022-a-5-5

The organization shall establish and maintain contact with relevant authorities.

iso-27001-2022-a-5-6

The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.

iso-27001-2022-a-5-9

An inventory of information and other associated assets, including owners, shall be developed and maintained.

iso-27001-2022-a-6-7

Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises.

iso-27001-2022-a-8-1

Information stored on, processed by or accessible using user end point devices shall be protected.

iso-27001-2022-a-8-10

Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.

iso-27001-2022-a-8-13

Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.