Skip to main content

Storage / Object

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.ObjStor.CN01Prevent Requests to Buckets or Objects with Untrusted KMS KeysPrevent any requests to object storage buckets or objects using untrusted KMS keys to protect against unauthorized data encryption, or sensitive data decryption.Encryption
2
3
4
CCC.ObjStor.CN02Enforce Uniform Bucket-level Access to Prevent Inconsistent PermissionsEnsure that uniform bucket-level access is enforced across all object storage buckets. This prevents the use of ad-hoc or inconsistent object-level permissions, ensuring centralized, consistent, and secure access management in accordance with the principle of least privilege.Access
1
1
2
CCC.ObjStor.CN03Prevent Bucket Deletion Through Irrevocable Bucket Retention PolicyEnsure that object storage bucket is not deleted after creation, and that the preventative measure cannot be unset.Data
1
2
2
CCC.ObjStor.CN04Objects have an Effective Retention Policy by DefaultEnsure that all objects stored in the object storage system have a retention policy applied by default, preventing premature deletion or modification of objects.Data
2
2
2
CCC.ObjStor.CN05Versioning is Enabled for All Objects in the BucketEnsure that versioning is enabled for all objects stored in the object storage bucket to enable recovery of previous versions of objects in case of loss or corruption.Data
1
2
4
CCC.ObjStor.CN07Multi-Factor Authentication Is Required for Object DeletionEnsure that deletion of objects stored in the object storage system is protected by multi-factor authentication (MFA), reducing the risk of accidental, unauthorized, or compromised-credential–based data destruction.Access
3
2
3

Imports

IDRemarks
CCC.Core.CN01Prevent Unencrypted Requests
CCC.Core.CN02Ensure Data Encryption at Rest for All Stored Data
CCC.Core.CN03Implement Multi-factor Authentication (MFA) for Access
CCC.Core.CN04Log All Access and Changes
CCC.Core.CN05Prevent Access from Untrusted Entities
CCC.Core.CN06Prevent Deployment in Restricted Regions
CCC.Core.CN07Alert on Unusual Enumeration Activity
CCC.Core.CN09Prevent Tampering, Deletion, or Unauthorized Access to Access Logs
CCC.Core.CN10Prevent Data Replication to Destinations Outside of Defined Trust Perimeter