Objective ISO/IEC 27002 13.1 applies. Control, in substance: whenever virtual networks are set up, their configuration is to be checked for consistency with the physical network, using the provider's network security policy as the yardstick. Cloud service customer: no additional guidance. Cloud service provider: define and document an information security policy for configuring virtual networks that is consistent with the information security policy for the physical network, and ensure the virtual network configuration matches that policy whatever means are used to create the configuration. Other information: virtual networks are configured on a virtual infrastructure over the physical network, and inconsistent policies can cause outages or defective access control; responsibility for configuring virtual networks can differ between customer and provider depending on the service type.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.