Besides general industry guides, the parks department's PaaS database offers a vendor-published security baseline tailored to that managed service. What should the operations team do?
Select an answer to reveal the explanation.
Short Explanation
The folks who built the managed database also published a hardening checklist for it—use that, not invent everything from scratch. Vendor baselines sit next to general guides like CIS, not instead of common sense. Turning provider security off for speed or relying on cage locks alone misses the cloud control plane.
Full Explanation
Vendor-specific security baselines for PaaS offerings complement general industry benchmarks by capturing service-specific settings and recommended defaults. Applying them where available strengthens configuration posture for managed databases and similar platforms. Ignoring vendor guidance, disabling provider security features, or relying solely on physical cage controls leaves managed-service misconfigurations unaddressed. Cloud+ best practices include both general and vendor baselines.