Cap One Project Projects-Scope
Cloud Governance & Perimeter - answer Ensure that all internet facing AWS hosted
business applications use Barracuda WAF (and not Mod Sec)
API Authentication (Threat Detection & Vulnerability Management) - answer-Capital
One has 120+ applications running in 44+ production AWS accounts. These identified
applications have internet facing endpoints with inconsistent or missing authentication
controls.
- All APIs (SOAP / REST etc.) that are exposed externally (barring APIs that are
approved for Anonymous access as they provide data classified for Public consumption)
need to meet our API Authentication ( oAuth, Mutual SSL or Open IG / User Tokens for
public clients) and other Cyber Security standards (Transport Layer Security,
Authorization, Protected via Barracuda WAF/ AWS Shield/ Shape etc.).
IAM Role Remediation (Access Management) - answer-This initiative is to help ensure
all AWS IAM credentials used by humans and machines follow least privilege.
-Capital One has grown to 300+ AWS accounts and each account hosts applications
with varied access requirements. Access permissions (machine roles/IAM roles) were
provisioned manually prior to in-house developed Avenue tool (mid-2018) with
automated guardrails.
-Cloud engineering will be rolling out policy validations in waves. The objective is to
make sure all ASVs incorporate required changes to comply to the standards.
High-Severity Vulnerability Findings(Security Metrics and Reporting) - answerAll high
vulnerability findings are remediated within the appropriate timeframe.
• High vulnerabilities for applications are remediated within 14 days of discovery.
• High vulnerabilities for infrastructure are remediated within 60 days of discovery.
Please note that we are only currently tracking Dynamic and OSS vulnerabilities. Other
vulnerability types will be tracked in the future.
Medium Severity Vulnerability Findings (Security Metrics and Reporting) - answerAll
applications are expected to remediate their vulnerability findings reported by different
cyber scanning tools within 45 days of discovery for applications and 60 days of
discovery for infrastructure. All applicable medium severity findings (e.g. from Cyber
cyber testing categories detailed in the "Detailed Guidance" section) are in scope for
remediation.
Secrets Management (Access Management) - answer-What actions should LoBs take
for SSH Key Compliance
-Securing AWS System Accounts and Begin onboarding all BA/ASV Machine to
Machine (M2M) secrets into CoS
- Register Human Secrets in CyberArk
Cloud Governance & Perimeter - answer Ensure that all internet facing AWS hosted
business applications use Barracuda WAF (and not Mod Sec)
API Authentication (Threat Detection & Vulnerability Management) - answer-Capital
One has 120+ applications running in 44+ production AWS accounts. These identified
applications have internet facing endpoints with inconsistent or missing authentication
controls.
- All APIs (SOAP / REST etc.) that are exposed externally (barring APIs that are
approved for Anonymous access as they provide data classified for Public consumption)
need to meet our API Authentication ( oAuth, Mutual SSL or Open IG / User Tokens for
public clients) and other Cyber Security standards (Transport Layer Security,
Authorization, Protected via Barracuda WAF/ AWS Shield/ Shape etc.).
IAM Role Remediation (Access Management) - answer-This initiative is to help ensure
all AWS IAM credentials used by humans and machines follow least privilege.
-Capital One has grown to 300+ AWS accounts and each account hosts applications
with varied access requirements. Access permissions (machine roles/IAM roles) were
provisioned manually prior to in-house developed Avenue tool (mid-2018) with
automated guardrails.
-Cloud engineering will be rolling out policy validations in waves. The objective is to
make sure all ASVs incorporate required changes to comply to the standards.
High-Severity Vulnerability Findings(Security Metrics and Reporting) - answerAll high
vulnerability findings are remediated within the appropriate timeframe.
• High vulnerabilities for applications are remediated within 14 days of discovery.
• High vulnerabilities for infrastructure are remediated within 60 days of discovery.
Please note that we are only currently tracking Dynamic and OSS vulnerabilities. Other
vulnerability types will be tracked in the future.
Medium Severity Vulnerability Findings (Security Metrics and Reporting) - answerAll
applications are expected to remediate their vulnerability findings reported by different
cyber scanning tools within 45 days of discovery for applications and 60 days of
discovery for infrastructure. All applicable medium severity findings (e.g. from Cyber
cyber testing categories detailed in the "Detailed Guidance" section) are in scope for
remediation.
Secrets Management (Access Management) - answer-What actions should LoBs take
for SSH Key Compliance
-Securing AWS System Accounts and Begin onboarding all BA/ASV Machine to
Machine (M2M) secrets into CoS
- Register Human Secrets in CyberArk