Views:
Trend Vision One™ – Cloud Posture provides a number of tools to help organizations quickly assess their infrastructure’s compliance posture against various compliance standards and frameworks:
Compliance tools:

Procedure

  1. Standard and Framework checks report - view how your organization’s infrastructure is tracking against rules filter by various Standards and Frameworks
  2. Compliance and Cloud Posture Reports - view and download a report assessing how your cloud infrastructure security and governance posture is tracking against controls from various Standards and Frameworks.
  3. Compliance Excel Report - Downloadable Excel report of your infrastructure’s compliance posture.
  4. Compliance Score – health metric of your cloud infrastructure measured against Cloud Posture’s entire 750+ rule set.

What to do next

Supported Standards and Frameworks Parent topic

Cloud Posture currently offers reports for the following standards and frameworks. Each standard or framework is made up of controls that specify security and governance requirements. Cloud Posture rules are mapped to these controls and the resulting checks can be filtered to display only the rules relevant to a particular standard or framework.
Standard or Framework
AWS Well Architected Framework
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
Azure Well Architected
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
(NIST) 800-53 (Rev.4)
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
(NIST) 800-53 (Rev.5)
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
Payment Card Industry Data Security Standard (PCI DSS)V3.2.1
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
Health Insurance Portability and Accountability Act of 1996 (HIPAA) 45cfr164
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
General Data Protection Regulation (GDPR)
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
Australian Prudential Regulation Authority (APRA) CPS 234
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
Monetary Authority of Singapore Technology Risk Management Guidelines (MAS TRM) 2021
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
NIST Cyber Security Framework v1.1
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
System and Organization Controls (SOC 2)
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
ISO 27001 Ed2 2013
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
AusGov ISM 2020
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
ASAE 3150 Security of CDR Data
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
HITRUST CSF v9.3
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
FEDRAMP Rev4
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
NIS Europe OES-2019
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
FISC Security v9
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
LGPD Brazil
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
The Centre of Internet Security (CIS) Benchmarks for Amazon Web Services Foundations v1.5.0
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
The Centre of Internet Security (CIS) Microsoft Azure Foundations Benchmark v1.5.0
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png
ISO 27001:2022
check=599d21a3-4a92-48a6-96f0-2390bf1d0db2.png

Standard and Framework checks report Parent topic

Procedure

  1. Open All checks report
  2. Select View by Rule or by Resource
  3. Expand Filter checks
  4. Check a standard or framework in Standards & Frameworks. For Example: Monetary Authority of Singapore TRM
    We currently support the following Standards & Framework filters:
    • AWS Well Architected Framework
    • Azure Well Architected
    • NIST 800-53 (Rev. 4)
    • NIST 800-53 (Rev. 5)
    • PCI DSS v3.2.1
    • HIPAA 45cfr164
    • ASAE 3150 Security of CDR Data
    • GDPR
    • APRA CPS 234
    • Monetary Authority of Singapore (MAS) TRM 2021
    • System and Organization Controls 2 (SOC2)
    • NIST Cyberscecurity Framework v1.1
    • ISO 27001 Ed2 2013
    • AusGov ISM 2020
    • HITRUST CSF v9.3
    • FEDRAMP Rev 4
    • NIS Europe OES-2019
    • FISC Security v9
    • LGPD (Brazil)
    • CIS Benchmarks for Amazon Web Services Foundations v1.5.0
    • CIS Microsoft Azure Foundations Benchmark v1.5.0
  5. Scroll down to the checks list, which will display the standard or framework selected. Click on a rule to see the check result (success or failure) against the rule for each resource. See Rules for more info.
  6. [ Optional ] Download the result as a PDF or CSV report.
    • Generate and download new Standard & Framework Checks results
      1. Click on Generate report
    • Download previously generated reports from the history
      1. Expand Other reports from the Configured reports list
      2. Select either CSV or PDF format for the report
    Note
    Note
    Standard and Framework checks reports can also be downloaded from All Generated Reports list. To know more about standards in a particular Standard and Framework report, in most cases you will need to register with the standard from their website to be able to access a detailed PDF about the standards.

What to do next

Compliance Excel Report Parent topic

A Compliance Excel Report is mapped in the same way as a Compliance & Cloud Posture Reports however this report is available in XLS format. Currently only supported for the following CIS AWS Foundations:
  • The Centre of Internet Security (CIS) GCP Foundations Benchmark v1.2.0
  • CIS Benchmarks for Amazon Web Services Foundations v1.5.0
  • CIS Microsoft Azure Foundations Benchmark v1.5.0
  • CIS Google Cloud Platform Foundations Benchmark v1.3.0

Example CIS AWS Foundations report Parent topic

compliance-excel-report-gkb4tk=168b5cbf-ff06-4625-9256-dae0004d7b81.png
{.zoom}