Cybersecurity GRC 15 items
Cloud Security Posture Management (CSPM) Review
Reviews a CSPM program covering cloud asset discovery, misconfiguration detection, policy-as-code guardrails, drift, and remediation across multi-cloud environments.
CISNIST 800-53CSA CCM
Free PDF · enter your email to download.
Coverage & Discovery
- Are all cloud accounts, subscriptions, and projects onboarded into the CSPM tool? *
- Is asset discovery continuous so new resources are detected automatically? *
- Are all in-scope cloud providers (AWS, Azure, GCP) covered by the CSPM platform? *
- Is CSPM integrated with the cloud provider audit logs (CloudTrail, Activity Log, Cloud Audit Logs)? *
Misconfiguration Detection
- Are findings benchmarked against CIS Foundations Benchmarks for each cloud provider? *
- Are public exposure risks (open storage buckets, public IPs, 0.0.0.0/0 rules) flagged as high severity? *
- Are encryption-at-rest and in-transit gaps detected across storage and databases? *
- Are overly permissive IAM roles and unused credentials identified? *
Guardrails & Prevention
- Are preventive guardrails (SCPs, Azure Policy, Org Policy) enforced to block risky configurations? *
- Is policy-as-code used so guardrails are version-controlled and peer-reviewed?
- Is configuration drift from an approved baseline detected and alerted? *
Remediation & Reporting
- Are findings assigned severity, an owner, and a remediation SLA? *
- Are auto-remediation workflows available for high-confidence, low-risk findings?
- Is posture score trended over time and reported to leadership?
- What percentage of critical findings are remediated within SLA?
Download the full Cloud Security Posture Management (CSPM) Review checklist
Get it as a clean, printable PDF — free.
