| ID | Title | Objective | Control Family | Threat Mappings | Guideline Mappings | Assessment Requirements |
|---|---|---|---|---|---|---|
| CCC.VPC.CN01 | Restrict Default Network Creation | Restrict the automatic creation of default virtual networks and related resources during subscription initialization to avoid insecure default configurations and enforce custom network policies. | Networking | 1 | 4 | 1 |
| CCC.VPC.CN02 | Limit Resource Creation in Public Subnet | Restrict the creation of resources in the public subnet with direct access to the internet to minimize attack surfaces. | Networking | 1 | 4 | 1 |
| CCC.VPC.CN03 | Restrict VPC Peering to Authorized Accounts | Ensure VPC peering connections are only established with explicitly authorized destinations to limit network exposure and enforce boundary controls. | Networking | 1 | 4 | 1 |
| CCC.VPC.CN04 | Enforce VPC Flow Logs on VPCs | Ensure VPCs are configured with flow logs enabled to capture traffic information. | Observability | 1 | 4 | 1 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.CN01 | Prevent Unencrypted Requests |
| CCC.Core.CN03 | Implement Multi-factor Authentication (MFA) for Access |
| CCC.Core.CN04 | Log All Access and Changes |
| CCC.Core.CN05 | Prevent Access from Untrusted Entities |
| CCC.Core.CN06 | Prevent Deployment in Restricted Regions |
| CCC.Core.CN07 | Alert on Unusual Enumeration Activity |
| CCC.Core.CN09 | Prevent Tampering, Deletion, or Unauthorized Access to Access Logs |