Cloud security posture managementedit

The Cloud Security Posture Management (CSPM) feature discovers and evaluates the services in your cloud environment — like storage, compute, IAM, and more — against configuration security guidelines defined by the Center for Internet Security (CIS) to help you identify and remediate risks that could undermine the confidentiality, integrity, and availability of your cloud data.

This feature currently supports Amazon Web Services (AWS). For a step-by-step getting started guide, refer to Get started with CSPM.

How CSPM worksedit

To set up the CSPM feature, you’ll install the CSPM integration for Elastic Agent in your cloud account(s).

Using the read-only credentials you will provide during the setup process, it will evaluate the configuration of resources in your environment every 4 hours. After each evaluation, the integration sends findings to Elastic. A high-level summary of the findings appears on the Cloud posture dashboard, and detailed findings appear on the Findings page.