Understand Risks with Insights
An Insight is a check on a specific behavior, condition, or characteristic of a cloud resource. Built from a continuously growing library of Query Filters, an Insight provides an in-depth understanding of your infrastructure’s security, compliance, optimization, or other characteristics that you specify. Insights can focus on specific characteristics or configuration issues, for example, to identify a network missing an internet gateway or to identify a database without encryption.
Some examples of common Insights include:
- Storage Container Exposing Access to the World
- Database Instance Publicly Accessible
- Volume Encryption Not Enabled
Insights provide customization, flexibility, and extensibility to support a variety of cloud environments. Cloud Security (InsightCloudSec) comes with a library of hundreds of built-in Insights. Check out the FAQ for more information.
Exploring Insights
Navigate to Security > Insights to begin exploring Insights. There are three navigational tabs for this feature:
- Library - A library containing all Insights that you or Cloud Security (InsightCloudSec) have created. The Library is the default view for Insights.
- Compliance Packs - A list of the Compliance Packs that Cloud Security (InsightCloudSec) has created. Compliance packs are groups of Insights that generally align to popular Compliance frameworks, for example, CIS - AWS 2.0.0, ISO 27017:2022. For more information, review Compliance Packs.
- Custom Packs - A list of the custom Insight packs your organization has created in Cloud Security (InsightCloudSec). For more information, review Custom Packs.
Using the Library
Use the filters on the page to narrow the view to the Insights you want to work with. You can take action on an Insight in two ways: using the quick actions at the top of the Library table or using the Action (…) menu. You can use the quick actions with multiple Insights. The following actions are available:
- Quick actions:
- Map to Compliance Pack - Adds the selected Insights to a custom pack and associates them with a selected compliance rule. Review Compliance pack mapping and rules for more information.
- Set Severity - Adjusts the severity of the selected Insights. You can also revert the severity to the default.
- Favorites - Adds the selected Insights to your favorites, which can be used to sort the Insights Library.
- Delete - Deletes the selected custom Insights.
- Clone - Clones the selected custom Insights.
- Action menu:
- View Insight Report - Opens the Insight Report, where you can see how your cloud accounts perform agains the Insight as well as basic Insight details and analytics.
- Map to Compliance Pack - Adds the Insight to a custom pack and associates them with a selected compliance rule. Review Compliance pack mapping and rules for more information.
- Add Labels - Adds a label for the Insight, which is a free-form text string that can used for taxonomy and categorization.
- Set Severity - Adjusts the severity of the Insight. You can also revert the severity to the default.
- Create Bot Automation - Creates a Bot from an Insight. Review Bot automations for more information.
- Favorites - Adds the Insight to your favorites, which can be used to sort the Insights Library.
- Delete - Deletes a custom Insight.
- Clone - Clones a custom Insight.
Compliance pack mapping and rules
After you have created a custom Insight pack and some custom compliance rules, you can add any Insight to your custom Insight pack and associate it with any rule in that pack. For more information on creating custom Insight packs and compliance rules, review Custom Packs.
To map an Insight to a pack:
- From the Command Platform, go to Controls & Compliance > Insights.
- Select one or more Insights.
- Click Map to Compliance Pack.
- Select a Compliance Pack. Only custom packs will show in this list.
- Select one or more Compliance Rule to map the Insight to.
- Click OK.
Exceptions
You can create an exception for a particular Insight using the Insights Library as a starting point. For more information on exceptions, review Exceptions.
To create an Exception for an Insight:
- From the Command Platform, go to Controls & Compliance > Insights.
- Click Total Findings. The Resources page opens and loads the resources that have an Insight finding.
- Select as many resources as needed.
- Click Add Exception.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The Exceptions are created.
Bot automations
The Insights Library is one of a few places in the Command Platform where you can create a Bot automation. Creating a Bot directly from an Insight allows you to skip some configuration steps and keeps the Bot scope as simple as possible. For more information on creating Bots, review Create a Bot.
To create a Bot for an Insight:
- Go to Security > Insights > Library, find the Insight, and click Action (…) > Create Bot Automation.
- For Bot Details:
- Enter a Bot Name.
- Optionally, enter a Category, Severity, and Description.
- Click Next.
- For Scope:
- Select Resource Types for the Bot to check. Selecting multiple resource types limits the number of applicable Query Filters.
- Select to scope resources by badge or by cloud account, Kubernetes cluster, or resource group.
- Select the preferred badges or cloud accounts, clusters, or resource groups.
- Click Next.
- For Query Filters:
- Click Add Query Filter.
- Find a Query Filter and click Apply.
- Configure the Query Filter as necessary.
- Repeat the previous steps until you have as many Query Filters as necessary. The Bot will only take action on resources that match all Query Filters.
- Click Next.
- For Actions:
- Click Add Action. Note: some actions can use Jinja2 templating and some can send notifications to an integration.
- Find an action and click Apply.
- Configure the action as necessary.
- Repeat the previous steps until you have as many actions as necessary. If you add multiple actions, note that all actions are executed instantly in parallel unless it’s a delayed action.
- Click Next.
- For Run Options:
- Click Select for each run option you want to implement.
- Set an execution threshold to prevent the Bot from running against more resources than expected:
- Select Set Resource Threshold.
- Enter the maximum number of resources the Bot can act on.
- Select the email addresses to notify when the threshold is reached.
- Click Save.
Using custom Insights
While Cloud Security (InsightCloudSec) includes an extensive library of built-in Insights, you can also create custom Insights. Custom Insights can be used to tailor Cloud Security (InsightCloudSec)-owned Insights to your specific needs or to create an Insight that Cloud Security (InsightCloudSec) may not have created quite yet.
To create a custom Insight:
- From the Command Platform, go to Assets & Identities > Resources.
- Optionally, click Scopes to open a panel containing the Clouds, Resource Groups, and Applications found in your Cloud Security (InsightCloudSec) organization and apply a specific scope.
- Click Query Filters, then select and configure at least one Query Filter.
- Click Save Insight.
- Provide a name, description, optional labels, and severity.
- Optionally, mark yourself as the owner of the Insight. If it the Insight is yours, it will not be visible to other users.
- Optionally, mark the Insight as a favorite. This will include it on the Summary page.
- Select at least one resource type for the Insight to apply to. Select the Include All checkbox to include all resource types.
- Click Submit. After saving, the Insight appears as a Custom Insight in the Insights Library.
To create a custom Insight from an existing Insight:
- From the Command Platform, go to Controls & Compliance > Insights.
- For a given Insight, click the Action menu (…).
- Click View Insight Report.
- Click View Results.
- Optionally, adjust the scope (Clouds, Resource Groups, Applications).
- Click Query Filters, then select and configure any additional Query Filters. You won’t be able to create a custom Insight if you don’t change the scope or the Query Filters.
- Click Save Insight.
- Provide a name, description, optional labels, and severity.
- Optionally, mark yourself as the owner of the Insight. If it the Insight is yours, it will not be visible to other users.
- Optionally, mark the Insight as a favorite. This will include it on the Summary page.
- Update the resource types as necessary. Select the Include All checkbox to include all resource types.
- Click Submit. After saving, the Insight appears as a Custom Insight in the Insights Library.
To edit the scope of a Custom Insight:
- From the Command Platform, go to Controls & Compliance > Insights.
- For a given Insight, click the Action menu (…).
- Click View Insight Report.
- Click View Results.
- Click Record Changes.
- Adjust the scope (Clouds, Resource Groups, Applications), edit existing Query Filters (using the pencil icon), or add Query Filters as necessary.
- Click Save Changes.
- Update the Insight information as necessary (for example: name, description, or severity).
- Click Submit.