Skip to main content

Storage / File Storage

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.FileStor.CN01Restrict NFS Mount to Approved Network SourcesEnsure that NFS mount and data-plane access is limited to explicitly approved virtual network sources within the organizational trust perimeter.Access
1
0
2
CCC.FileStor.CN02Enforce Least-Privilege POSIX File PermissionsEnsure that default and mapped POSIX permissions on the shared file system do not grant broader access than required by the workload.Access
1
0
2
CCC.FileStor.CN03Restrict Writable Mount Access to Authorized ClientsEnsure that write access to the shared file system is granted only to clients explicitly authorized for modification.Data
1
0
2
CCC.FileStor.CN04Enforce Storage Capacity QuotasEnsure that file system capacity growth is bounded by configured quotas to prevent exhaustion that disrupts dependent workloads.Resource
2
0
2
CCC.FileStor.CN05Restrict Snapshot Access for File SystemsEnsure that backup snapshots and replicas of the file system are not more accessible than the primary file system.Data
1
0
1
CCC.FileStor.CN06Monitor Performance Tier SaturationEnsure that throughput or IOPS saturation on the selected performance tier is detected before workloads experience unacceptable latency.Resource
2
0
2