| ID | Title | Objective | Control Family | Threat Mappings | Guideline Mappings | Assessment Requirements |
|---|---|---|---|---|---|---|
| CCC.Build.CN01 | Restrict Allowed Build Agents | Ensure that builds are executed only on authorized build agents to maintain control over the build environment and prevent unauthorized code execution. | Orchestration | 1 | 3 | 1 |
| CCC.Build.CN02 | Restrict Allowed External Services for Build Triggers | Ensure that builds can only be triggered by authorized external services or repositories to prevent unauthorized code execution or tampering. | Orchestration | 1 | 3 | 1 |
| CCC.Build.CN03 | Deny External Network Access for Build Environments | Ensure that build environments do not have external network access to prevent unauthorized external access and data exfiltration. | Networking | 2 | 3 | 1 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.CN01 | Prevent unencrypted requests |
| CCC.Core.CN02 | Ensure data encryption at rest for all stored data |
| CCC.Core.CN04 | Log all access and changes |
| CCC.Core.CN05 | Prevent access from untrusted entities |
| CCC.Core.CN09 | Prevent tampering, deletion, or unauthorized access to access logs |
| CCC.Core.CN10 | Prevent data replication to destinations outside of defined trust perimeter |