Skip to main content

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.VPC.CN01Restrict Default Network CreationRestrict the automatic creation of default virtual networks and related resources during subscription initialization to avoid insecure default configurations and enforce custom network policies.Networking141
CCC.VPC.CN02Limit Resource Creation in Public SubnetRestrict the creation of resources in the public subnet with direct access to the internet to minimize attack surfaces.Networking141
CCC.VPC.CN03Restrict VPC Peering to Authorized AccountsEnsure VPC peering connections are only established with explicitly authorized destinations to limit network exposure and enforce boundary controls.Networking141
CCC.VPC.CN04Enforce VPC Flow Logs on VPCsEnsure VPCs are configured with flow logs enabled to capture traffic information.Observability141

Imports

IDRemarks
CCC.Core.CN01Prevent Unencrypted Requests
CCC.Core.CN03Implement Multi-factor Authentication (MFA) for Access
CCC.Core.CN04Log All Access and Changes
CCC.Core.CN05Prevent Access from Untrusted Entities
CCC.Core.CN06Prevent Deployment in Restricted Regions
CCC.Core.CN07Alert on Unusual Enumeration Activity
CCC.Core.CN09Prevent Tampering, Deletion, or Unauthorized Access to Access Logs