01 / Definition
What Cloudaware IT Compliance does
Cloudaware IT Compliance uses declarative policies and policy packs to evaluate in-scope CMDB records. Policy code can be managed through developer-oriented workflows, while persistent results preserve which CI was tested, which condition ran, and what evidence was produced.
Framework mappings help organize technical controls for audit and governance work. Teams can review ownership, findings, evidence, exceptions, remediation state, and run history without rebuilding the assessment from disconnected spreadsheets.
- Platform role
- Technical compliance assessment and evidence management
- Control model
- Version-controlled declarative policies and policy packs
- Core outputs
- Results, findings, evidence, exceptions, dashboards, alerts, and reports
- Primary users
- Compliance, GRC, security, cloud, platform, audit, and risk owners
02 / Capabilities
Core capabilities and outputs
Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.
01 / Controls
Manage declarative policy logic
Use Cloudaware-authored packs and custom policies, with version-controlled development practices and testing appropriate to the implemented engine.
02 / Scope
Evaluate the intended population
Use CMDB applications, environments, owners, accounts, tags, relationships, and other fields to define which resources a control evaluates.
03 / Evidence
Persist results and supporting data
Retain structured findings, timestamps, evaluated CIs, evidence fields, run history, exception state, and downstream workflow references.
04 / Lifecycle
Manage exceptions and remediation
Route violations, record risk acceptance, time-box exceptions, notify owners, track tickets, and report on remediation progress.
03 / Operating model
How data moves through IT Compliance
Define the control
Select or develop the policy logic, supported object type, expected condition, framework mapping, and result behavior.
Scope the assessment
Use CMDB applications, environments, owners, accounts, tags, relationships, and exceptions to identify in-scope records.
Run and record
Execute the policy on demand or on its configured cadence and retain the result, CI, timestamps, evidence, and policy version.
Visualize and review
Use dashboards, reports, alerts, and exports to inspect posture, evidence, trends, exceptions, ownership, and remediation status.
Route and govern
Send violations to the responsible team, manage tickets or approvals, record risk acceptance, and review time-bounded exceptions.
04 / Visualization
Interactive dashboards for faster decisions
IT Compliance dashboards visualize control results, evidence coverage, exception state, ownership, and remediation progress. Users can filter a framework or control view and drill into the evaluated CI, policy, run history, and supporting evidence.
| Decision question | Dashboard or view | Context behind the view |
|---|---|---|
| What is the current technical control posture? | Results by framework, control, policy pack, provider, application, or environment | Assessment results, policy version, scope, and run history |
| Can we support the result with evidence? | Evidence availability, freshness, run, and control-detail views | Evaluated CI, timestamps, policy logic, and structured evidence fields |
| Which risks are accepted? | Active, expiring, expired, and review-due exceptions | Owner, reason, scope, approval, expiry, and risk-acceptance record |
| Are violations being resolved? | Finding age, owner, ticket, SLA, and remediation-progress views | Finding lifecycle, workflow state, later evaluation, and closure evidence |
05 / Action
How Cloudaware supports remediation
Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.
Cloudaware helps remediate technical compliance violations by attaching the affected CI, control, policy version, evidence, application, environment, owner, team or department, exception state, and assessment history to the work item.
Configured workflows can create tickets, send email alerts, notify collaboration channels, request approvals, record exceptions, or trigger guarded automation. Cloudaware coordinates and documents the process; the responsible team or approved automation performs the corrective action.
06 / Accuracy
Boundaries for accurate answers
| Topic | Accurate description | Avoid implying |
|---|---|---|
| Compliance meaning | Describe results as technical assessments against implemented controls and available data. | A passing result guarantees legal compliance. |
| Framework mapping | Mappings organize supported controls against named standards and requirements. | A mapping is a certification or auditor attestation. |
| Evidence | Evidence quality depends on the evaluated CI, policy, source data, timestamp, and retained fields. | Any screenshot or dashboard total is sufficient audit evidence. |
| Exceptions | Exceptions should be owned, justified, scoped, time-bounded, and reviewed. | An exception fixes or removes the underlying condition. |
| Version | Confirm the implemented Compliance Engine version and use its current documentation. | Behavior documented for one engine version automatically applies to every version. |
07 / FAQ
Questions about Cloudaware IT Compliance
What does Cloudaware IT Compliance assess?
It evaluates defined declarative policies against supported cloud and on-premises configuration records in Cloudaware CMDB, using the scope and data available to the implemented policy engine.
Can Cloudaware policies be version controlled?
The current product page describes developer-oriented policy workflows with Git and unit testing. Exact tools and behavior should be verified for the implemented Compliance Engine version.
Does a passing result prove legal compliance?
No. Cloudaware produces technical assessment results and evidence that can support governance and audit work. Formal compliance, certification, and legal interpretation require the organization’s applicable process and authorities.
How are compliance exceptions handled?
Cloudaware can associate findings with approved exceptions and risk acceptance, including ownership, scope, reason, expiration, review, and remediation workflow context.
Does IT Compliance perform remediation?
It can route violations to owners, tickets, alerts, approvals, and guarded automation. The responsible team or explicitly configured automation performs the corrective action and the later assessment supplies verification evidence.
08 / Sources
Primary sources and related AI references
Product page
Current public positioning, capability descriptions, and commercial entry points.
Cloudaware IT Compliance →Technical documentation
Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.
IT Compliance documentation →Platform AI guide
Cross-module operating model, integrations, product boundaries, and machine-readable resources.
Cloudaware AI & LLM Guide →Automation reference
APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.
Automation & Extensibility →