Module 02

Cloud security

Posture management that ranks by blast radius instead of rule name, pivots to the asset so an owner reads one page rather than nine tickets, and produces evidence auditors accept. Scanners run on nodes inside your own account.

/cloud/posture/findings
Snapshot public to the internet prod-eu-west · contains customer PII Critical
Role can assume into 12 accounts ci-deployer · 4% of granted permissions used Critical
Encryption drifted from known-good analytics-store · changed 3 days ago High
EU data resident in permitted region all sensitive stores · verified Pass
Ranked by blast radius Not by rule severity
What it covers

Accounts, posture, identity, exposure, evidence

Deliberately generic posture management. No AI-in-cloud positioning, no reinvented category — the boring, complete version of a thing you already need.

Accounts

Connected accounts and subscriptions with provider, regions, scan cadence and the last successful scan — plus a full resource inventory filterable by type, tag and owner.

  • Role or service-principal setup with permission preview
  • Dry run before the first real scan
  • Scan health: failures, throttling, drift on the scanner role itself

Posture

Misconfiguration findings ranked by what an attacker could actually reach, pivoted both ways — by finding for the security team, by resource for the owner.

  • Drift, with the before and after state side by side
  • Exceptions with expiry dates that reopen automatically
  • Generated fixes, assignable to an owner in one action

Identity and entitlements

Granted versus used permissions for every principal, with a right-sized policy you can propose rather than a percentage you cannot act on.

  • Keys and secrets: age, rotation, last use, never-used
  • Cross-account trust paths that reach sensitive resources
  • Human versus machine split — service identities usually win

Data exposure

Buckets, disks, snapshots, databases and endpoints reachable from the internet — and what class of data each one holds.

  • Encryption at rest and in transit, with CMK coverage
  • Residency: sensitive data outside its permitted region
  • Sensitive stores and exactly who can reach them

Benchmarks

Control-by-control state against CIS, ISO 27001, SOC 2, PCI DSS and NIST — with the artefact each control produced attached to it.

  • Runs with pass rate and delta since the last assessment
  • Evidence: API responses, timestamps, captured state
  • Gaps — controls with no evidence source at all

Drift to code

Deployed state that no longer matches the Terraform claiming to define it — the bridge between this module and code security.

  • Fix at the source rather than in the console
  • Modules ranked by how many repos inherit a defect
  • One finding, two modules, no duplicate ticket
Ranking

Blast radius, not rule name.

"S3 bucket policy allows public read" tells an engineer nothing about whether to drop what they are doing. "This bucket is internet-reachable, holds customer PII, and a CI role in another account can write to it" tells them everything.

  • Reachability first. Findings on resources nothing can reach sink to the bottom automatically.
  • One page per owner. Nine findings on one resource arrive as one page, not nine tickets.
  • Exceptions expire. Accepted risk carries an owner, a reason and a date — and reopens when it passes.

analytics-exports · s3

blast radius
Internet reachable yes
Data classes present PII, financial
Principals with write 6 (2 cross-acct)
Defined in infra/data.tf
Critical Fix in source
Compliance

Evidence produced. Not certification claimed.

We will never tell you that you are SOC 2 compliant — that is not ours to say. What we will do is assemble the artefact behind every control, timestamped and attributable, and show you the controls where no evidence source exists at all. Auditors consistently prefer the honest gap list.

  • Five frameworks mapped. CIS, ISO 27001, SOC 2, PCI DSS and NIST, control by control.
  • Exportable packs. One bundle per audience — auditor, board, engineering backlog.
  • Deltas between runs. Show what improved since last quarter without rebuilding the spreadsheet.
How evidence reaches reports
Framework Controls Evidence Δ
CIS Benchmark241229 attached+18
ISO 2700111496 attached+7
SOC 2 Type II6461 attached+3
PCI DSS 4.07870 attached+11
NIST 800-53189142 attached+22

Connect one account. See the blast radius.

Read-only role, permission preview, dry run first. You will have findings before the call ends.

No credit card. No agent on the endpoint. Nothing leaves your network.