Compliance Packs
Copy link

Compliance packs are built-in collections of related Insights focused on industry requirements and standards for all of your resources. Compliance packs may focus on security, costs, governance, or combinations of these across a variety of frameworks, for example, HIPAA, PCI DSS, and GDPR.

Compliance packs cannot be deleted or edited. If you need to edit a compliance pack for your needs, you can create a custom Insight pack based on an existing compliance pack. For more information, review create a Custom Insight Pack.

List of supported compliance frameworks

Compliance PackDescription
ACSC Cloud Security Controls Matrix (ISM Sep22)Contains Insights that assist with compliance for the Australian Cyber Security Centre (ACSC) Cloud Controls Matrix (CCM).
ACSC Essential 8Contains Insights that assist with compliance for the ACSC Essential Eight Maturity Model. See the ACSC’s website  for more information.
AWS Foundational Security Best PracticesContains Insights that assist with compliance for the Amazon Web Services (AWS) Foundational Security Best Practices standard. See the AWS Documentation  for more information.
AWS Privilege Escalation AttacksContains Insights that assist with preventing common privilege escalation attacks in AWS.
Azure SecurityContains Insights that assist with adhering to Microsoft Defender for Cloud Recommendations.
Canadian Centre for Cyber SecurityContains Insights that assist with compliance for the Canadian Centre for Cyber Security (CCCS).
CIS - AKS KubernetesContains Insights that assist with compliance for the CIS Azure Kubernetes Service (AKS) benchmark. See the CIS’ website  for more information.
CIS Azure Database ServicesContains Insights that assist with compliance for the CIS Azure Database Services benchmark. See the CIS’ website  for more information.
CIS - KubernetesContains Insights that assist with compliance for the CIS Kubernetes benchmark. See the CIS’ website  for more information.
CIS - Alibaba Cloud Foundation BenchmarkContains Insights that assist with compliance for the Center for Internet Security (CIS) Alibaba 1.0 benchmark. See the CIS’ website  for more information.
CIS - Amazon Web Services Foundations BenchmarkContains Insights that assist with compliance for the CIS AWS benchmark. See the CIS’ website  for more information.
CIS - AWS End User Compute Services BenchmarkContains Insights that assist with compliance for the CIS AWS End User Compute Services benchmark. See the CIS’ website  for more information.
CIS - ControlsContains Insights that assist with compliance for the CIS Critical Security Controls framework. See the CIS’ website  for more information.
CIS - Google Cloud Platform Foundation BenchmarkContains Insights that assist with compliance for the CIS GCP benchmark. See the CIS’ website  for more information.
CIS - Microsoft Azure Compute Services BenchmarkContains Insights that assist with compliance for the CIS Azure Compute Services benchmark. See the CIS’ website  for more information.
CIS - Microsoft Azure Foundations BenchmarkContains Insights that assist with compliance for the CIS Azure Foundations benchmark. See the CIS’ website  for more information.
CIS - Microsoft Azure Storage Services BenchmarkContains Insights that assist with compliance for the CIS Azure Storage Services benchmark. See the CIS’ website  for more information.
CIS - Oracle Cloud Infrastructure Foundations BenchmarkContains Insights that assist with compliance for the CIS Oracle Cloud Infrastructure (OCI) Foundations benchmark. See the CIS’ website  for more information.
CMMCContains Insights that assist with compliance for the Cybersecurity Maturity Model Certification. See the CyberAssist website  for more information.
Cost Containment PackContains Insights that assist with identifying common resources and configurations that could increase costs for your organization.
CSA CCMContains Insights that assist with compliance for the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) framework. See the CSA’s website  for more information.
CVEs for ISTIOContains Insights that assist with compliance for the Common Vulnerabilities and Exposures system for Istio.
FedRAMP CCMContains Insights that assist with compliance for FedRAMP CCM framework.
FedRAMP Low BaselineContains Insights that assist with compliance for the FedRAMP low impact level. See the FedRAMP website  for more information.
FedRAMP Moderate BaselineContains Insights that assist with compliance for the FedRAMP moderate impact level. See the FedRAMP website  for more information.
FFIECContains Insights that assist with adhering to the Federal Financial Institutions Examination Council (FFIEC) cybersecurity requirements. See the FFIEC website  for more information.
GDPRContains Insights that assist with adhering to the European Union (EU) General Data Protection Regulation (GDPR) requirements. See the GDPR website  for more information.
HIPAAContains Insights that assist with adhering to the Health Insurance Portability and Accountability Act (HIPAA) requirements. See the HIPAA website  for more information.
HITRUSTContains Insights that assist with compliance for the Health Information Trust (HITRUST) Alliance Common Security Framework (CSF). See the HITRUST  website for more information.
IAM Security (with Access Explorer)Contains Insights that assist with mitigating AWS IAM security risk (requires Access Explorer).
IAM Security (without Access Explorer)Contains Insights that assist with mitigating AWS IAM security risk (does not require Access Explorer).
ISO 27001:2022Contains Insights that assist with compliance for the International Organization for Standardization (ISO) 27001:2022 framework. See the ISO 27001:2022  website for more information.
ISO 27017:2015Contains Insights that assist with compliance for the ISO 27017:2015 framework. See the ISO 27017:2015  website for more information.
Kubernetes Security RecommendedContains Insights that assist with adhering to Kubernetes Security best practices and recommendations.
Microsoft Cloud Security BenchmarkContains Insights that assist with compliance for the Microsoft cloud security benchmark. See the Microsoft documentation  for more information.
MITRE Att&ck Mitigation PackContains Insights that assist with adhering to MITRE’s ATT&CK knowledge base of tactics and techniques. See the ATT&CK website  for more information.
NIST 800-171Contains Insights that assist with compliance for the National Institute of Standards and Technology (NIST) 800-171 framework. See the NIST  website for more information.
NIST 800-53Contains Insights that assist with compliance for the NIST 800-171. See the NIST  website for more information.
NIST Cyber Security FrameworkContains Insights that assist with compliance for the NIST Cybersecurity Framework (CSF). See the NIST  website for more information.
NSA and CISA Kubernetes Hardening GuideContains Insights that assist with compliance for National Security Agency (NSA) and Cybersecurity & Infrastructure Security Agency (CISA) Kubernetes Hardening guide. See the CISA website  for more information.
NYDFS NYCRR 500Contains Insights that assist with compliance for New York State Department of Financial Services (NYDFS) New York Codes, Rules, and Regulations (NYCRR) part 500 (a.k.a the Cybersecurity Regulation). See the NYDFS website  for more information.
PCI DSSContains Insights that assist with compliance for the Payment Card Industry (PCI) Data Security Standard (DSS). See the PCI website  for more information.
Rapid7 AI/ML Security Best PracticesContains Insights that assist with compliance for the Open Worldwide Application Security Project’s (OWASP) Top 10 Vulnerabilities for Machine Learning, the OWASP Top 10 for LLMs, and Insights checking if best practice configurations have been implemented. This pack utilizes 11 controls:
  • Data Poisoning: Manipulating training data to influence how a model makes decisions. Controls here include secure storage, enforcing least privilege, access control, and monitoring.
  • Model Poisoning: Manipulating a model itself to influence how it behaves. Controls here include encryption techniques, access control, and monitoring.
  • Transfer Learning: Training a model on a specific task, but fine-tuning it on a different one to influence decision making. Controls here include secure storage, access control, and monitoring.
  • Model Inversion: Reverse-engineering a model to understand how it works and how it may be influenced. Controls here include encryption, secure storage, access control, and monitoring.
  • Model Stealing: Gaining access to a model and its parameters. Controls here include encryption, secure storage, access control, and monitoring.
  • Model Skewing: Manipulating the distribution of training data to influence a model’s decision making. Controls here include secure storage, access control, and monitoring.
  • Excessive Permissions: Overly permissive roles and policies can lead to manipulation of systems, services, and data models. Controls here include strong authentication, access controls, and enforcing least privilege.
  • Denial of Service: Repeated resource-heavy operations may lead to service degradation and increased cost. Controls here include strong authentication and access controls.
  • Supply Chain Compromise: Modifying or replacing a third-party library used by the system, or its data. Controls here include monitoring source control integrations and library lifecycle management.
  • Membership Inference: Manipulating training data to cause it to reveal sensitive information such as Personal Identifiable Information (PII) and Protected Health Information (PHI). Controls here include monitoring behavior for anomalies.
  • Output Integrity: Modifying the output from a machine learning model to negatively impact downstream business processes or systems. Controls here include monitoring behavior for anomalies and auditing interactions between the model and its partner systems.
SOC 2Contains Insights that assist with compliance for the Service Organization Control (SOC) Type 2 cybersecurity framework.

Explore Compliance Packs
Copy link

The Compliance Packs tab displays all the built-in Insight packs for Cloud Security (InsightCloudSec).

To open the Compliance Packs tab:

  1. From the Command Platform, go to Controls & Compliance > Insights.
  2. Click Compliance Packs.

Each compliance pack in the display includes a brief description of the pack, the number of Insights included in the pack, the number of subscriptions for the pack, and when the pack was created or last updated. Click Action (…) to open the Actions menu for a Compliance Pack. Some actions include:

  • Open Pack Details - Display the Insights and compliance rules associated with the pack as well as basic compliance reporting for your cloud accounts. For more information, review Pack details and reporting.
  • Go to Misconfigurations - Open the compliance pack in the Misconfigurations feature.
  • Create Email Subscription - Create a scheduled reporting email for this compliance pack. For more information, review Subscriptions and exports.
  • Manage Subscriptions - Manage existing email subscriptions for this compliance pack. For more information, review Subscriptions and exports.
  • Filter Insight Library by Pack - Open the Insight Library automatically filtered to the compliance pack.
  • Manage Cloud Storage Subscription Links - Manage existing cloud storage subscriptions (also known as export configuration links) for this compliance pack. For more information, review Subscriptions and exports.
  • Disable Pack Visibility - Hide this compliance pack from the view.

Pack details and reporting

Opening the Pack Details displays all Insights associated with the compliance pack as well as the compliance rule matched to the Insight. Compliance rules for built-in compliance packs cannot be edited. If you need to edit a compliance pack for your needs, you can create a custom Insight pack based on an existing compliance pack. For more information, review create a Custom Insight Pack.

You can filter the list by compliance rule, or you can free-text search for Insight metadata like name, author, or release version. The actions available on the Pack Details tab are the same as the actions available in the Insights Library:

  • View Insight Report - Open the Insight Report, where you can see how your cloud accounts perform against the Insight as well as basic Insight details and analytics.
  • Map to Compliance Pack - Add the Insight to a custom pack and associates them with a selected compliance rule. Review Compliance pack mapping and rules for more information.
  • Add Labels - Add a label for the Insight, which is a free-form text string that can used for taxonomy and categorization.
  • Set Severity - Adjust the severity of the Insight. You can also revert the severity to the default.
  • Create Bot Automation - Create a Bot from an Insight. Review Bot automations for more information.
  • Favorites - Add the Insight to your favorites, which can be used to sort the Insights Library.
  • Delete - Delete a custom Insight.
  • Clone - Clone a custom Insight.

The other tab in the Pack details is Compliance Reporting. This tab displays trends and analytics graphs as well as data related to how compliant your cloud accounts are against the compliance pack.

You can also manage subscriptions and export configuration links using the Options button. For more information, review Subscriptions and exports.

Subscriptions and exports

You can export your compliance reporting data using two methods: email subscriptions and export configuration links (also called cloud storage subscriptions). For more information on managing email subscriptions or export configuration links, review Compliance Exporting.

ℹ️

We recommend using Misconfigurations instead

While the process documented for Compliance Exporting is still supported, we strongly recommend users take advantage of the capabilities and functionality that are included with the Misconfigurations for better data visibility, reporting, and context around compliance.