Cloud Security Posture Management Report

CSPM helps in identifying and mitigating risks related to security misconfigurations and vulnerabilities, ensuring compliance with security standards.

Select Account

  • On the CSPM Dashboard, click the Select Accounts dropdown to view all cloud accounts available under your profile.

  • Each account will be labeled based on its cloud provider (e.g., Azure, AWS, GCP).

  • Check the box next to the desired account(s) to include them in your report. The selected account will be highlighted (e.g., BT-FinOps Azure).

  • You can select multiple accounts if you have access to more than one.

  • Once the selection is complete, proceed to the next step.

Generate Report

After selecting the account(s), click the Generate Report button located on the right side of the dashboard.
The system will automatically begin scanning all selected resources within the chosen account(s) to analyze their current security configuration and compliance posture.

Once the analysis is complete, the dashboard displays:


  • Overall Security Score (%) – Indicates the overall strength of your cloud security configuration.


  • Resources with Issues – Shows the number of resources that have detected security issues.

  • Active Alerts – Displays the count of current active alerts requiring attention.

  • High-Risk Resources – Highlights resources classified as high-risk based on issue severity.

Overview Tab

The Overview tab provides a summarized view of your organization’s current security posture.
It includes visual charts and metrics that help you understand risk distribution and identify areas that require immediate remediation.

Sections:

  • Security Trends Analysis – Tracks security posture changes over time.

  • Top 10 Affected Resources – Highlights resources most impacted by security issues. Clicking any bar reveals detailed issue information.

  • Critical Issues – Displays a color-coded circular chart summarizing all critical issues detected (e.g., MFA not enabled, encryption not enforced, insecure access permissions).

Risk Distribution Tab

The Risk Distribution tab offers a deeper breakdown of your security risks across various dimensions such as severity, resource type, and issue category.

Key Components:


  • Security Resources Table – Displays detailed information for each affected resource, including:


    • Resource Name – Name of the affected resource.

    • Severity – Risk level (High, Medium, Low).

    • Score – Resource-specific security score (out of 100).

    • Resource ID – Unique identifier of the resource.

    • Resource Type – Example: AADUser, VM, StorageAccount.

    • Cloud Provider – Example: Azure, AWS.

    • Security Issue – Description of the detected issue (e.g., MFA not enabled).

    • Security Domain – The affected security area (e.g., Identity, Network, Encryption).

Exporting Reports

After reviewing the dashboard results, you can export the data in multiple formats:


  • PDF – For visual reports and presentations.


  • Excel – For detailed data analysis and sharing with security or compliance teams.

Use the Export icon located at the top-right corner of the CSPM dashboard to download the report.
These reports can then be shared with your Security, Compliance, or FinOps teams for further investigation and remediation planning.

Was this article helpful?

0 out of 0 liked this article

Still need help? Message Us