Compliance Packs
Compliance packs are built-in collections of related Insights focused on industry requirements and standards for all of your resources. Compliance packs may focus on security, costs, governance, or combinations of these across a variety of frameworks, for example, HIPAA, PCI DSS, and GDPR.
Compliance packs cannot be deleted or edited. If you need to edit a compliance pack for your needs, you can create a custom Insight pack based on an existing compliance pack. For more information, review create a Custom Insight Pack.
List of supported compliance frameworks
| Compliance Pack | Description |
|---|---|
| ACSC Cloud Security Controls Matrix (ISM Sep22) | Contains Insights that assist with compliance for the Australian Cyber Security Centre (ACSC) Cloud Controls Matrix (CCM). |
| ACSC Essential 8 | Contains Insights that assist with compliance for the ACSC Essential Eight Maturity Model. See the ACSC’s website for more information. |
| AWS Foundational Security Best Practices | Contains Insights that assist with compliance for the Amazon Web Services (AWS) Foundational Security Best Practices standard. See the AWS Documentation for more information. |
| AWS Privilege Escalation Attacks | Contains Insights that assist with preventing common privilege escalation attacks in AWS. |
| Azure Security | Contains Insights that assist with adhering to Microsoft Defender for Cloud Recommendations. |
| Canadian Centre for Cyber Security | Contains Insights that assist with compliance for the Canadian Centre for Cyber Security (CCCS). |
| CIS - AKS Kubernetes | Contains Insights that assist with compliance for the CIS Azure Kubernetes Service (AKS) benchmark. See the CIS’ website for more information. |
| CIS Azure Database Services | Contains Insights that assist with compliance for the CIS Azure Database Services benchmark. See the CIS’ website for more information. |
| CIS - Kubernetes | Contains Insights that assist with compliance for the CIS Kubernetes benchmark. See the CIS’ website for more information. |
| CIS - Alibaba Cloud Foundation Benchmark | Contains Insights that assist with compliance for the Center for Internet Security (CIS) Alibaba 1.0 benchmark. See the CIS’ website for more information. |
| CIS - Amazon Web Services Foundations Benchmark | Contains Insights that assist with compliance for the CIS AWS benchmark. See the CIS’ website for more information. |
| CIS - AWS End User Compute Services Benchmark | Contains Insights that assist with compliance for the CIS AWS End User Compute Services benchmark. See the CIS’ website for more information. |
| CIS - Controls | Contains Insights that assist with compliance for the CIS Critical Security Controls framework. See the CIS’ website for more information. |
| CIS - Google Cloud Platform Foundation Benchmark | Contains Insights that assist with compliance for the CIS GCP benchmark. See the CIS’ website for more information. |
| CIS - Microsoft Azure Compute Services Benchmark | Contains Insights that assist with compliance for the CIS Azure Compute Services benchmark. See the CIS’ website for more information. |
| CIS - Microsoft Azure Foundations Benchmark | Contains Insights that assist with compliance for the CIS Azure Foundations benchmark. See the CIS’ website for more information. |
| CIS - Microsoft Azure Storage Services Benchmark | Contains Insights that assist with compliance for the CIS Azure Storage Services benchmark. See the CIS’ website for more information. |
| CIS - Oracle Cloud Infrastructure Foundations Benchmark | Contains Insights that assist with compliance for the CIS Oracle Cloud Infrastructure (OCI) Foundations benchmark. See the CIS’ website for more information. |
| CMMC | Contains Insights that assist with compliance for the Cybersecurity Maturity Model Certification. See the CyberAssist website for more information. |
| Cost Containment Pack | Contains Insights that assist with identifying common resources and configurations that could increase costs for your organization. |
| CSA CCM | Contains Insights that assist with compliance for the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) framework. See the CSA’s website for more information. |
| CVEs for ISTIO | Contains Insights that assist with compliance for the Common Vulnerabilities and Exposures system for Istio. |
| FedRAMP CCM | Contains Insights that assist with compliance for FedRAMP CCM framework. |
| FedRAMP Low Baseline | Contains Insights that assist with compliance for the FedRAMP low impact level. See the FedRAMP website for more information. |
| FedRAMP Moderate Baseline | Contains Insights that assist with compliance for the FedRAMP moderate impact level. See the FedRAMP website for more information. |
| FFIEC | Contains Insights that assist with adhering to the Federal Financial Institutions Examination Council (FFIEC) cybersecurity requirements. See the FFIEC website for more information. |
| GDPR | Contains Insights that assist with adhering to the European Union (EU) General Data Protection Regulation (GDPR) requirements. See the GDPR website for more information. |
| HIPAA | Contains Insights that assist with adhering to the Health Insurance Portability and Accountability Act (HIPAA) requirements. See the HIPAA website for more information. |
| HITRUST | Contains Insights that assist with compliance for the Health Information Trust (HITRUST) Alliance Common Security Framework (CSF). See the HITRUST website for more information. |
| IAM Security (with Access Explorer) | Contains Insights that assist with mitigating AWS IAM security risk (requires Access Explorer). |
| IAM Security (without Access Explorer) | Contains Insights that assist with mitigating AWS IAM security risk (does not require Access Explorer). |
| ISO 27001:2022 | Contains Insights that assist with compliance for the International Organization for Standardization (ISO) 27001:2022 framework. See the ISO 27001:2022 website for more information. |
| ISO 27017:2015 | Contains Insights that assist with compliance for the ISO 27017:2015 framework. See the ISO 27017:2015 website for more information. |
| Kubernetes Security Recommended | Contains Insights that assist with adhering to Kubernetes Security best practices and recommendations. |
| Microsoft Cloud Security Benchmark | Contains Insights that assist with compliance for the Microsoft cloud security benchmark. See the Microsoft documentation for more information. |
| MITRE Att&ck Mitigation Pack | Contains Insights that assist with adhering to MITRE’s ATT&CK knowledge base of tactics and techniques. See the ATT&CK website for more information. |
| NIST 800-171 | Contains Insights that assist with compliance for the National Institute of Standards and Technology (NIST) 800-171 framework. See the NIST website for more information. |
| NIST 800-53 | Contains Insights that assist with compliance for the NIST 800-171. See the NIST website for more information. |
| NIST Cyber Security Framework | Contains Insights that assist with compliance for the NIST Cybersecurity Framework (CSF). See the NIST website for more information. |
| NSA and CISA Kubernetes Hardening Guide | Contains Insights that assist with compliance for National Security Agency (NSA) and Cybersecurity & Infrastructure Security Agency (CISA) Kubernetes Hardening guide. See the CISA website for more information. |
| NYDFS NYCRR 500 | Contains Insights that assist with compliance for New York State Department of Financial Services (NYDFS) New York Codes, Rules, and Regulations (NYCRR) part 500 (a.k.a the Cybersecurity Regulation). See the NYDFS website for more information. |
| PCI DSS | Contains Insights that assist with compliance for the Payment Card Industry (PCI) Data Security Standard (DSS). See the PCI website for more information. |
| Rapid7 AI/ML Security Best Practices | Contains Insights that assist with compliance for the Open Worldwide Application Security Project’s (OWASP) Top 10 Vulnerabilities for Machine Learning, the OWASP Top 10 for LLMs, and Insights checking if best practice configurations have been implemented. This pack utilizes 11 controls:
|
| SOC 2 | Contains Insights that assist with compliance for the Service Organization Control (SOC) Type 2 cybersecurity framework. |
Explore Compliance Packs
The Compliance Packs tab displays all the built-in Insight packs for Cloud Security (InsightCloudSec).
To open the Compliance Packs tab:
- From the Command Platform, go to Controls & Compliance > Insights.
- Click Compliance Packs.
Each compliance pack in the display includes a brief description of the pack, the number of Insights included in the pack, the number of subscriptions for the pack, and when the pack was created or last updated. Click Action (…) to open the Actions menu for a Compliance Pack. Some actions include:
- Open Pack Details - Display the Insights and compliance rules associated with the pack as well as basic compliance reporting for your cloud accounts. For more information, review Pack details and reporting.
- Go to Misconfigurations - Open the compliance pack in the Misconfigurations feature.
- Create Email Subscription - Create a scheduled reporting email for this compliance pack. For more information, review Subscriptions and exports.
- Manage Subscriptions - Manage existing email subscriptions for this compliance pack. For more information, review Subscriptions and exports.
- Filter Insight Library by Pack - Open the Insight Library automatically filtered to the compliance pack.
- Manage Cloud Storage Subscription Links - Manage existing cloud storage subscriptions (also known as export configuration links) for this compliance pack. For more information, review Subscriptions and exports.
- Disable Pack Visibility - Hide this compliance pack from the view.
Pack details and reporting
Opening the Pack Details displays all Insights associated with the compliance pack as well as the compliance rule matched to the Insight. Compliance rules for built-in compliance packs cannot be edited. If you need to edit a compliance pack for your needs, you can create a custom Insight pack based on an existing compliance pack. For more information, review create a Custom Insight Pack.
You can filter the list by compliance rule, or you can free-text search for Insight metadata like name, author, or release version. The actions available on the Pack Details tab are the same as the actions available in the Insights Library:
- View Insight Report - Open the Insight Report, where you can see how your cloud accounts perform against the Insight as well as basic Insight details and analytics.
- Map to Compliance Pack - Add the Insight to a custom pack and associates them with a selected compliance rule. Review Compliance pack mapping and rules for more information.
- Add Labels - Add a label for the Insight, which is a free-form text string that can used for taxonomy and categorization.
- Set Severity - Adjust the severity of the Insight. You can also revert the severity to the default.
- Create Bot Automation - Create a Bot from an Insight. Review Bot automations for more information.
- Favorites - Add the Insight to your favorites, which can be used to sort the Insights Library.
- Delete - Delete a custom Insight.
- Clone - Clone a custom Insight.
The other tab in the Pack details is Compliance Reporting. This tab displays trends and analytics graphs as well as data related to how compliant your cloud accounts are against the compliance pack.
You can also manage subscriptions and export configuration links using the Options button. For more information, review Subscriptions and exports.
Subscriptions and exports
You can export your compliance reporting data using two methods: email subscriptions and export configuration links (also called cloud storage subscriptions). For more information on managing email subscriptions or export configuration links, review Compliance Exporting.
We recommend using Misconfigurations instead
While the process documented for Compliance Exporting is still supported, we strongly recommend users take advantage of the capabilities and functionality that are included with the Misconfigurations for better data visibility, reporting, and context around compliance.