What is Cloud security posture management (CSPM)?
Tools and processes that continuously check cloud environments such as Azure, AWS and GCP for misconfigurations and compliance gaps against best-practice benchmarks.
How it works
Most cloud breaches come from misconfiguration rather than flaws in the cloud provider: storage left public, overly broad permissions, logging turned off. CSPM checks configurations continuously against benchmarks such as the CIS Foundations Benchmarks.
CSPM findings need owners and fixes, just like vulnerabilities.
Key points
- Continuous configuration checking
- Benchmarks such as CIS Foundations
- Covers identity, storage, network and logging
- Findings must be owned and fixed
Common questions
Do cloud providers include CSPM?
Each major provider offers native posture tools, such as Microsoft Defender for Cloud, AWS Security Hub and Google Security Command Center.
Is a cloud security review the same thing?
A review is a point-in-time expert assessment; CSPM is continuous tooling. They complement each other.
Talk to someone who does this every day
Questions about CSPM? Our team will give you a straight answer.