A cloud team wants to evaluate the security posture of their infrastructure. Which evidence source provides the most objective, standardized baseline?
-
A
Internal team self-assessments
-
B
CIS Benchmarks or NIST frameworks applied via automated compliance scanning tools
-
C
Vendor security certification documentation
-
D
Informal peer review from another team