ctl-016
Policy-as-code blocks non-compliant cloud resource deployment.
- Type
- PREVENTIVE
- Automation
- AUTOMATED
- Frequency
- CONTINUOUS
- Owner
- Cloud Platform Team
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the guardrail policy definitions; confirm they cover the cloud security baselines the organization requires.
- 2.Confirm the guardrails are enforced as a deployment-time gate rather than a post-deployment detective check.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Attempt to deploy a non-compliant test resource and confirm the guardrail blocks it.
- 2.Select 25 production deployments across the period and confirm none bypassed the guardrail policy.
- 3.Review guardrail policy change logs to confirm no unauthorized weakening occurred during the period.
Linked risks
- Cloud misconfiguration exposuremitigation 3
- Cloud program governance gapsmitigation 2
Framework mappings & latest test
CCC-06CCC-07
Latest test:PARTIAL2026-04-15