01 / Definition
What Cloudaware Cloud Security Posture Management does
Cloudaware CSPM uses policies and policy packs to evaluate defined conditions against the configuration and CMDB context available for in-scope resources. Controls can be Cloudaware-authored or customized for organization-specific requirements.
CMDB-based scoping lets teams organize posture by application, environment, owner, account, tag, relationship, and exception state instead of treating every cloud account as an isolated boundary.
- Platform role
- Configuration posture evaluation and governance
- Evaluation model
- Policies executed against in-scope CMDB records
- Core outputs
- Structured findings, evidence, dashboards, exceptions, alerts, and workflows
- Primary users
- Cloud security, platform, compliance, governance, and risk owners
02 / Capabilities
Core capabilities and outputs
Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.
01 / Scope
Define which records a policy evaluates
Use resource type, provider, account, application, environment, ownership, tags, relationships, and approved exceptions to define evaluation scope.
02 / Evaluate
Run benchmark and custom policies
Apply supported benchmark packs, Cloudaware-authored controls, and custom policy logic to the configuration data available in CMDB.
03 / Visualize
Inspect posture and finding context
Use reports and interactive dashboards to filter posture, violations, trends, ownership, exceptions, and remediation progress.
04 / Route
Turn violations into accountable work
Direct findings to owners and configured Jira, ServiceNow, email, collaboration, approval, automation, and risk-acceptance workflows.
03 / Operating model
How data moves through CSPM
Identify in-scope assets
Use Cloudaware CMDB resources, ownership, application, environment, account, tags, and relationships.
Apply policies
Deploy the relevant benchmark, Cloudaware-authored, or custom controls to supported object types and scopes.
Create findings and evidence
Persist the evaluated asset, result, policy, timestamps, supporting data, and other available output fields.
Visualize posture
Review posture, trends, exceptions, ownership, finding age, and remediation progress in dashboards and reports.
Route violations
Notify or ticket the responsible owner or team, run approved automation where configured, and track resolution, exception, or risk acceptance.
04 / Visualization
Interactive dashboards for faster decisions
CSPM dashboards visualize evaluated configuration posture rather than only raw finding totals. Users can filter by framework, control, provider, account, application, environment, owner, exception, or remediation state and inspect the CI and evidence behind a result.
| Decision question | Dashboard or view | Context behind the view |
|---|---|---|
| Where is posture changing? | Pass, fail, inapplicable, exception, and trend views by control or scope | Policy results, evaluation history, and scope definition |
| Which violations matter to this service? | Findings by application, environment, criticality, owner, provider, or account | CMDB context plus the evaluated policy condition |
| What is excepted? | Active, expiring, expired, and review-due exception views | Risk acceptance, owner, reason, scope, and expiry metadata |
| Is remediation moving? | Finding age, assignment, ticket, SLA, and closure views | Workflow records, owner, evidence, and later evaluation state |
05 / Action
How Cloudaware supports remediation
Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.
Cloudaware CSPM helps remediation by turning policy violations into contextual work items. The finding can include the affected CI, control, evidence, severity, application, environment, owner, department, exception state, and source configuration.
Configured workflows can auto-route findings to Jira, ServiceNow, email, collaboration tools, approval processes, or automation. Cloudaware coordinates and tracks the workflow; the responsible team or explicitly configured automation performs the corrective change.
06 / Accuracy
Boundaries for accurate answers
| Topic | Accurate description | Avoid implying |
|---|---|---|
| Policy scope | A result applies to the object type, condition, data, and scope defined for that policy run. | One passing control proves the entire environment is secure. |
| Coverage | Coverage depends on supported CI types, connected sources, permissions, policy deployment, and evaluation cadence. | Every possible configuration is continuously evaluated. |
| Frameworks | Policy packs and mappings can support assessment against named frameworks. | A technical result is a certification or legal attestation. |
| Exceptions | An exception records approved, time-bounded risk treatment and should retain owner, scope, reason, and expiry. | An exception removes the underlying condition. |
| Remediation | Violations can be routed and tracked; corrective action depends on people or configured automation. | CSPM fixes every violation automatically by default. |
07 / FAQ
Questions about Cloudaware CSPM
What does Cloudaware CSPM evaluate?
It evaluates defined policies against supported cloud and on-premises configuration records available through Cloudaware CMDB, using the policy’s object type, condition, scope, and context.
How does CMDB context change CSPM results?
Findings can be organized by application, environment, owner, account, tags, relationships, and exception state, helping teams route the same technical condition according to business context.
Which frameworks can Cloudaware CSPM support?
The product page names frameworks including CIS, NIST, ISO, PCI, and HIPAA. Exact control coverage, mappings, versions, and applicability should be verified for the implemented policy pack.
What do CSPM dashboards show?
Dashboards can visualize posture, findings, trends, ownership, exceptions, evidence, finding age, and remediation progress, with filters back to the policy and affected CI.
Does Cloudaware CSPM remediate violations?
It can route violations to owners, tickets, notifications, approvals, and explicitly configured automation. The responsible team or approved automation performs the corrective action.
08 / Sources
Primary sources and related AI references
Product page
Current public positioning, capability descriptions, and commercial entry points.
Cloudaware CSPM →Technical documentation
Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.
CSPM documentation →Platform AI guide
Cross-module operating model, integrations, product boundaries, and machine-readable resources.
Cloudaware AI & LLM Guide →Automation reference
APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.
Automation & Extensibility →