Security Operations

CSPM – Cloud Configuration

Misconfigurations with evidence, guidance and score history

Cloud accounts change faster than any documentation. A storage bucket is opened for a test, a role widened for a migration, an exception set for a weekend. It is rarely rolled back. CSPM therefore checks accounts continuously against a catalog: Entra ID and M365 via Microsoft Graph, Azure via the ARM API, AWS via the SDK, Google Cloud and OTC via their respective REST interfaces, everything else via the Prowler import. Every violation becomes a finding with a severity, the excerpt of the API response as evidence and guidance for portal, CLI and Terraform. All access is read-only. The module changes nothing in your cloud.

BSI C5ISO 27001NIS2DORA
Features

Your benefits

1

Read-only, without exception

Reader role, SecurityAudit policy, Graph read scopes. The module deliberately performs no automatic remediation and provides the instructions instead. A tool that assesses your cloud should not also be allowed to change it.

2

Context decides the severity

Four factors per resource: internet-exposed, privileged, sensitive data, unencrypted. Only their combination raises a finding, and by exactly one level. The catalog severity remains visible alongside, together with the rule that raised it.

3

Works without outbound access

Instances without internet access run the module entirely through the Prowler import: Prowler runs on your side, the OCSF result arrives by upload or API. Unknown checks register themselves in the catalog along the way.

4

Exception instead of "accepted"

An accepted finding stays visibly open. Only an exception with justification, scope and optional expiry removes the check from the score denominator. It remains visible as its own metric and in the auditor PDF, and once it expires a daily job closes it again.

Capabilities

All capabilities at a glance

  • Native collectors for Entra ID/M365, Azure, AWS, Google Cloud and OTC/OpenStack
  • Prowler import (OCSF) for any further provider, by upload or API
  • "Test connection" checks each permission step separately and names missing rights
  • Findings with evidence from the API response and guidance for portal, CLI and Terraform
  • Context factors per resource, raised only on combination and only by one level
  • Rule editor: context rules are data and can be changed per instance
  • Deduplicated per account, check and resource, with first and last sighting
  • Automatic closing only after a complete run, never on partial API failures
  • Exceptions with justification, scope, expiry and optional four-eyes approval
  • Compliance view per framework, BSI C5 first, plus ISO 27001, NIS2 and DORA
  • Immutable score snapshots per run, overall and per framework
  • Cockpit with score history, severity distribution and sync health of all accounts
  • The tenant Microsoft Secure Score is imported and tracked with every run
  • Create a measure, task or exception directly from any finding
  • Auditor PDF, ASM correlation, drift timeline and Checkov import
Result

A score that discloses how it is calculated, and a list whose order can be justified.

Experience CSPM – Cloud Configuration live

Schedule a no-obligation demo – we will show you the module with your own use cases.