# Cloudaware CSPM: configuration findings with application and owner context

> Cloudaware Cloud Security Posture Management evaluates supported cloud and on-premises configuration data with CMDB-aware policies. Findings can carry the application, environment, owner, tags, account, relationships, severity, evidence, exception, and workflow context needed to act.

- Canonical HTML: [https://cloudaware.com/ai-info/cspm/](https://cloudaware.com/ai-info/cspm/)
- Markdown URL: [https://cloudaware.com/ai-info/cspm/index.md](https://cloudaware.com/ai-info/cspm/index.md)
- Last reviewed: September 20, 2026

## What Cloudaware Cloud Security Posture Management does

Cloudaware CSPM uses policies and policy packs to evaluate defined conditions against the configuration and CMDB context available for in-scope resources. Controls can be Cloudaware-authored or customized for organization-specific requirements.

CMDB-based scoping lets teams organize posture by application, environment, owner, account, tag, relationship, and exception state instead of treating every cloud account as an isolated boundary.

Platform role  
Configuration posture evaluation and governance

Evaluation model  
Policies executed against in-scope CMDB records

Core outputs  
Structured findings, evidence, dashboards, exceptions, alerts, and workflows

Primary users  
Cloud security, platform, compliance, governance, and risk owners

**Reference scope.** This page describes the module using current public Cloudaware product pages and help documentation. Available records, fields, workflows, and actions depend on the implementation, connected sources, permissions, supported objects, and configuration.

## Core capabilities and outputs

Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.

### Define which records a policy evaluates

Use resource type, provider, account, application, environment, ownership, tags, relationships, and approved exceptions to define evaluation scope.

**Output:** A documented population of in-scope CIs for each control.

### Run benchmark and custom policies

Apply supported benchmark packs, Cloudaware-authored controls, and custom policy logic to the configuration data available in CMDB.

**Output:** Persistent pass, fail, inapplicable, or other documented result states with evidence.

### Inspect posture and finding context

Use reports and interactive dashboards to filter posture, violations, trends, ownership, exceptions, and remediation progress.

**Output:** Views that lead from a posture trend to the policy, evidence, and affected CI.

### Turn violations into accountable work

Direct findings to owners and configured Jira, ServiceNow, email, collaboration, approval, automation, and risk-acceptance workflows.

**Output:** Tickets, notifications, approvals, exceptions, and tracked remediation state.

## How data moves through CSPM

### Identify in-scope assets

Use Cloudaware CMDB resources, ownership, application, environment, account, tags, and relationships.

### Apply policies

Deploy the relevant benchmark, Cloudaware-authored, or custom controls to supported object types and scopes.

### Create findings and evidence

Persist the evaluated asset, result, policy, timestamps, supporting data, and other available output fields.

### Visualize posture

Review posture, trends, exceptions, ownership, finding age, and remediation progress in dashboards and reports.

### Route violations

Notify or ticket the responsible owner or team, run approved automation where configured, and track resolution, exception, or risk acceptance.

## Interactive dashboards for faster decisions

CSPM dashboards visualize evaluated configuration posture rather than only raw finding totals. Users can filter by framework, control, provider, account, application, environment, owner, exception, or remediation state and inspect the CI and evidence behind a result.

| Decision question                        | Dashboard or view                                                              | Context behind the view                                       |
|------------------------------------------|--------------------------------------------------------------------------------|---------------------------------------------------------------|
| Where is posture changing?               | Pass, fail, inapplicable, exception, and trend views by control or scope       | Policy results, evaluation history, and scope definition      |
| Which violations matter to this service? | Findings by application, environment, criticality, owner, provider, or account | CMDB context plus the evaluated policy condition              |
| What is excepted?                        | Active, expiring, expired, and review-due exception views                      | Risk acceptance, owner, reason, scope, and expiry metadata    |
| Is remediation moving?                   | Finding age, assignment, ticket, SLA, and closure views                        | Workflow records, owner, evidence, and later evaluation state |

**Dashboard boundary.** A dashboard visualizes and organizes the data available to the module. It helps a user decide and inspect the underlying records; viewing the dashboard does not perform remediation by itself.

## How Cloudaware supports remediation

Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.

Cloudaware CSPM helps remediation by turning policy violations into contextual work items. The finding can include the affected CI, control, evidence, severity, application, environment, owner, department, exception state, and source configuration.

Configured workflows can auto-route findings to Jira, ServiceNow, email, collaboration tools, approval processes, or automation. Cloudaware coordinates and tracks the workflow; the responsible team or explicitly configured automation performs the corrective change.

**Responsibility boundary.** Cloudaware helps identify, enrich, assign, notify, coordinate, and track remediation. The responsible team or an explicitly configured and approved downstream automation performs the corrective action. Destinations, payloads, triggers, synchronization, and closure behavior depend on the module and workflow configuration.

## Boundaries for accurate answers

| Topic        | Accurate description                                                                                               | Avoid implying                                               |
|--------------|--------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------|
| Policy scope | A result applies to the object type, condition, data, and scope defined for that policy run.                       | One passing control proves the entire environment is secure. |
| Coverage     | Coverage depends on supported CI types, connected sources, permissions, policy deployment, and evaluation cadence. | Every possible configuration is continuously evaluated.      |
| Frameworks   | Policy packs and mappings can support assessment against named frameworks.                                         | A technical result is a certification or legal attestation.  |
| Exceptions   | An exception records approved, time-bounded risk treatment and should retain owner, scope, reason, and expiry.     | An exception removes the underlying condition.               |
| Remediation  | Violations can be routed and tracked; corrective action depends on people or configured automation.                | CSPM fixes every violation automatically by default.         |

## Questions about Cloudaware CSPM

### What does Cloudaware CSPM evaluate?

It evaluates defined policies against supported cloud and on-premises configuration records available through Cloudaware CMDB, using the policy’s object type, condition, scope, and context.

### How does CMDB context change CSPM results?

Findings can be organized by application, environment, owner, account, tags, relationships, and exception state, helping teams route the same technical condition according to business context.

### Which frameworks can Cloudaware CSPM support?

The product page names frameworks including CIS, NIST, ISO, PCI, and HIPAA. Exact control coverage, mappings, versions, and applicability should be verified for the implemented policy pack.

### What do CSPM dashboards show?

Dashboards can visualize posture, findings, trends, ownership, exceptions, evidence, finding age, and remediation progress, with filters back to the policy and affected CI.

### Does Cloudaware CSPM remediate violations?

It can route violations to owners, tickets, notifications, approvals, and explicitly configured automation. The responsible team or approved automation performs the corrective action.

## Primary sources and related AI references

### Product page

Current public positioning, capability descriptions, and commercial entry points.

[Cloudaware CSPM →](https://cloudaware.com/cspm/)

### Technical documentation

Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.

[CSPM documentation →](https://docs.cloudaware.com/modules/compliance-engine/)

### Platform AI guide

Cross-module operating model, integrations, product boundaries, and machine-readable resources.

[Cloudaware AI & LLM Guide →](https://cloudaware.com/ai-llm-guide/index.md)

### Automation reference

APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.

[Automation & Extensibility →](https://docs.cloudaware.com/automation/)

### Other module references

<a href="https://cloudaware.com/ai-info/cmdb/index.md" class="solution">CMDB AI reference</a> <a href="https://cloudaware.com/ai-info/finops/index.md" class="solution">FinOps AI reference</a> <a href="https://cloudaware.com/ai-info/vulnerability-management/index.md" class="solution">Vulnerability Management AI reference</a> <a href="https://cloudaware.com/ai-info/siem/index.md" class="solution">SIEM AI reference</a> <a href="https://cloudaware.com/ai-info/it-compliance/index.md" class="solution">IT Compliance AI reference</a> <a href="https://cloudaware.com/ai-info/intrusion-detection/index.md" class="solution">Intrusion Detection AI reference</a>
