Misconfigurations (formerly Compliance Scorecard)
The Misconfigurations page helps you quickly identify resources that are most at risk, have a security impact, or affect your compliance goals. You can also create exemptions and view remediation details directly from the interface to streamline misconfiguration management.
New experience available
Clicking the Switch to Modern UI button in the top right corner replaces the Compliance Scorecard with the Misconfigurations page. The Compliance Scorecard (Legacy UI) is on by default and you can toggle between the interfaces at anytime. The Misconfigurations page is designed to make compliance workflows faster, more consistent, and easier to use without losing any of your current functionality, including exports. With Misconfigurations, you can:
- Diagnose misconfigurations more efficiently in the context of the standards that matter most.
- Visualize exemption status to streamline reviews and remediation.
- Gain increased performance for quicker risk analysis and compliance posture checks.
- Manage cloud infrastructure more effectively with improved tag visibility.
Prerequisites
Before using the Misconfigurations page, make sure at least one cloud account is connected to InsightCloudSec. While not required, it’s helpful to understand Insights and Compliance Packs.
Explore misconfigurations
In InsightCloudSec, a misconfiguration is a resource with security configuration that results in an Insight finding. There’s a large variety of Insights for all resource and cloud account types. Insights also provide criteria for Compliance Packs, which can be used to audit your environment.
To view your misconfigurations:
- Log in to InsightCloudSec.
- Go to Security > Misconfigurations.
You can filter the displayed resources using:
- Filters: Select an item or status and click Apply.
- Scopes: Select a scope, including cloud accounts, badges, or compliance packs and click Apply Scope.
The filter options change based on the current display:
- By Resource (default): Resources are shown. Expand a resource to see its Insight findings.
- By Insight: Insights are shown, but scopes are unavailable. Expand an Insight to view affected resources.
Share and take action on misconfigurations
The Misconfigurations page provides many options for sharing and remediating misconfigurations, reducing the time it takes to assess and take ownership of remediation activities.
View resource details
Click a resource name or switch to Display By: Resource and click Action (…) > View Resource Details. To learn more about resources and their properties, see Resources.
Subscribe to misconfigurations
Need to manage existing subscriptions?
After you create a subscription, you can reconfigure it, delete it, or run it on demand from the Manage Subscriptions page. Cloud storage subscriptions also have the option to validate settings and to be toggled on or off. From the Misconfigurations page, click Share > Manage Subscriptions.
To create an email subscription:
- Go to Security > Misconfigurations.
- Filter or scope the page if needed.
- Click Share > Create Email Subscription.
- Select a Compliance Pack. If you scoped to a Compliance Pack, it will automatically be selected.
- Enter a Subscription Name.
- Select Recipient Email Addresses. The email subscription can only go to an existing user in InsightCloudSec.
- Configure the Email Frequency as needed.
- Optionally, include tags or badges, which adds respective columns to the sheet.
- Click OK.
To create a cloud storage subscription:
- Go to Security > Misconfigurations.
- Filter or scope the page if needed.
- Click Share > Create Cloud Storage Subscription.
- Select a Compliance Pack. If you scoped to a Compliance Pack, it will automatically be selected.
- Enter an Export Name.
- Select a Storage Container Resource. The cloud storage container must be already harvested by InsightCloudSec, which means it appears in the Resources Inventory.
- Optionally, enter a Storage Container Prefix to change the path for subscription delivery. By default, the subscription is sent to the root level of the container.
- Optionally, include tags or badges, which adds respective columns to the sheet.
- Optionally, select to export the subscription as an
.xlsx
file (the default is a.zip
file). - Click OK. The Misconfiguration Report is delivered at 3:00 (UTC) every day.
Take action on misconfigurations
To manage tags:
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Filter or scope the page if needed.
- Next to a resource, click Action (…) > Manage Tag(s). The resource properties panel opens to the Tags tab.
- Add or remove tags as needed.
To assign ownership:
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Filter or scope the page if needed.
- Next to a resource, click Action (…) > Assign Owner.
- Select an InsightCloudSec user to associate as an owner.
- Click OK.
To view contextual cloud account-based actions:
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Filter or scope the page if needed.
- Next to a resource, click Action (…) > View Resource Actions.
Actions relevant to the selected resource appear. The cloud account associated with the resource needs special permissions (referred to as an Automation Full Access policy or role) to perform any of these actions.
To create a Bot for an Insight:
- Go to Security > Misconfigurations.
- Switch to Display By: Insight.
- Filter or scope the page if needed.
- Next to a resource, click Action (…) > Create Bot. The Create Bot page opens with some information already provided.
See Creating a Bot for more instructions.
To view remediation details:
- Go to Security > Misconfigurations.
- Switch to Display By: Insight.
- Filter or scope the page if needed.
- Next to a resource, click Action (…) > View Remediation Details. The Insight Information panel opens.
Exempt resources from misconfigurations
Exemptions exclude a resource from being assessed by a specific Insight. Use exemptions for compliant resources that do not require further evaluation. You can view all existing Exemptions and manage them from the Exemptions page.
Exempt a resource (Display By: Resource)
To create an exemption (select an Insight):
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Optionally, filter or scope the page as necessary.
- Next to a resource, click Action > Create Exemption.
- Select an Insight.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The exemption is created.
To create an exemption for a resource:
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Optionally, filter or scope the page as necessary.
- Expand a resource.
- Next to an Insight, click Action > Create Exemption.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The exemption is created.
To create multiple exemptions for a resource:
- Go to Security > Misconfigurations.
- Switch to Display By: Resource.
- Optionally, filter or scope the page as necessary.
- Expand a resource.
- Select as many Insights as desired.
- Click Create Exemption.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The exemptions are created.
Exempt a resource (Display By: Insight)
To create an exemption for an Insight:
- Go to Security > Misconfigurations.
- Switch to Display By: Insight.
- Optionally, filter or scope the page as necessary.
- Expand an Insight.
- Next to a resource, click Action > Create Exemption.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The exemption is created.
To create multiple exemptions for an Insight:
- Go to Security > Misconfigurations.
- Switch to Display By: Insight.
- Optionally, filter or scope the page as necessary.
- Expand an Insight.
- Select as many resources as desired.
- Click Create Exemption.
- Select a Start Date.
- Optionally, select an Expiration Date.
- Enter an Approver Email.
- Optionally, enter Notes.
- Click Create. The exemptions are created.
Use the Compliance Scorecard (legacy UI)
Legacy UI details
!!!(_shared/CRC-ICS/compliance-scorecard.md)!!!