Privileged Access to the Cloud Console
Provide system screenshots or a system-generated list demonstrating which users and systems are able to make changes to your production cloud console.
Changes to the cloud console include the ability to:
Modify customer application configurations or customer data through the application
Deploy code changes to the application
Additional Guidance
Ensure that you have included all methods and users that are capable of making changes in your cloud console.
If some permissions or users are pulled from, or reliant on, other systems, your evidence should reflect this.
These systems can be complicated. As such, it's helpful for auditors if you explain these interactions in the Evidence Description.
Example Evidence.
AWS
GCP
Azure
Associated Unified Control ID | Associated Framework Control |
CTRL-9 | LCL-32 |