Skip to main content

Compliance Frameworks

Cloudgeni provides continuous compliance monitoring against major security frameworks. Track your compliance posture, generate audit-ready reports, and remediate violations with AI-powered assistance.

What You'll Get

  • 5 major frameworks - SOC2, ISO27001, NIS2, PCI DSS, CIS
  • Multi-cloud coverage - AWS, Azure, GCP, OCI
  • 1000+ security rules - Powered by Prowler
  • PDF compliance reports - Audit-ready documentation

Supported Frameworks

SOC 2

Service Organization Control 2 - Trust Services Criteria for service organizations.
CategoryControls
SecurityAccess controls, encryption, network security
AvailabilityDisaster recovery, redundancy, monitoring
Processing IntegrityData validation, error handling
ConfidentialityData classification, encryption at rest
PrivacyData handling, consent management
Supported Providers: AWS, Azure, GCP

ISO 27001:2022

International standard for information security management systems (ISMS).
DomainFocus Areas
A.5Information security policies
A.6Organization of information security
A.7Human resource security
A.8Asset management
A.9Access control
A.10Cryptography
A.11-A.18Physical, operations, communications, development
Supported Providers: AWS, Azure, GCP

NIS 2

EU Network and Information Security Directive (2022/2555).
RequirementDescription
Risk ManagementSecurity policies and risk assessments
Incident HandlingDetection, response, and reporting
Business ContinuityBackup, disaster recovery
Supply ChainThird-party security
EncryptionCryptography and key management
Supported Providers: AWS, Azure, GCP

PCI DSS 4.0

Payment Card Industry Data Security Standard version 4.0.
RequirementFocus
1-2Network security controls
3-4Protect account data
5-6Vulnerability management
7-8Access control measures
9-10Physical security, monitoring
11-12Testing, policies
Supported Providers: AWS, Azure, GCP

CIS 3.0

Center for Internet Security Benchmarks version 3.0.
SectionFocus
IdentityIAM, MFA, access reviews
LoggingAudit trails, monitoring
NetworkingVPCs, firewalls, encryption
StorageEncryption, access controls
ComputeInstance security, patching
Supported Providers: OCI (Oracle Cloud Infrastructure)

Framework Coverage by Provider

FrameworkAWSAzureGCPOCI
SOC 2YesYesYes-
ISO 27001YesYesYes-
NIS 2YesYesYes-
PCI DSS 4.0YesYesYes-
CIS 3.0---Yes

Compliance Scoring

How Scores Are Calculated

Compliance score is calculated based on finding status:
Score = (PASSED + SKIPPED) / Total Findings × 100
Finding StatusCounts As
PASSEDCompliant
SKIPPEDNot applicable (compliant)
FAILEDNon-compliant
MANUALRequires manual review

Score Interpretation

Score RangeStatusAction
90-100%ExcellentMaintain current controls
75-89%GoodAddress high-priority gaps
50-74%Needs WorkPrioritize remediation
Below 50%CriticalImmediate attention required

Control-Level Scoring

Each framework control is scored individually:
  • Pass: All checks for the control pass
  • Partial: Some checks pass, some fail
  • Fail: Critical checks fail

Dashboard Features

Compliance Score Widget

The main dashboard displays:
  • Overall compliance score percentage
  • Trend over time (7-day, 30-day)
  • Score breakdown by framework
  • Comparison to previous period

Framework Progress

For each framework:
  • Progress bar showing compliance percentage
  • Count of passed/failed controls
  • List of critical violations
  • Quick links to findings

Control Breakdown

Drill down into specific controls:
  1. Click on a framework
  2. View controls grouped by category
  3. See pass/fail status for each control
  4. Access related findings

PDF Compliance Reports

Generating Reports

  1. Go to Compliance in the dashboard
  2. Select the framework
  3. Click Generate Report
  4. Configure filters:
    • Date range
    • Severity levels
    • Status (all, failed only)
    • Regions
  5. Click Download PDF

Report Contents

SectionContents
Executive SummaryOverall score, trends, highlights
Framework OverviewFramework description, scope
Score SummaryBreakdown by category
Control DetailsPer-control status and findings
Findings ListAll findings with severity
RecommendationsPrioritized remediation steps

Report Customization

OptionDescription
Include PassedShow passing controls
Include EvidenceAttach finding details
Executive OnlySummary without details
Custom LogoAdd your organization logo

Finding Management

Severity Levels

LevelDescriptionSLA Recommendation
CriticalImmediate security risk24 hours
HighSignificant vulnerability7 days
MediumModerate risk30 days
LowMinor issue90 days
InfoInformationalAs needed

Finding Status

StatusMeaning
OpenFinding detected, not addressed
In ProgressRemediation underway
ResolvedFinding fixed and verified
SuppressedAccepted risk (documented)
False PositiveIncorrectly flagged

Status Workflow

Open → In Progress → Resolved

    Suppressed (with justification)

Remediation

AI-Powered Fixes

For each finding, Cloudgeni can:
  1. Analyze the non-compliant configuration
  2. Generate IaC code to fix the issue
  3. Validate the fix against policies
  4. Create a pull request

Remediation Workflow

  1. Select a finding
  2. Click Remediate
  3. Review AI-generated fix
  4. Approve and create PR
  5. Merge to apply fix

Bulk Remediation

Address multiple findings at once:
  1. Filter findings by type or control
  2. Select multiple findings
  3. Click Bulk Remediate
  4. Review consolidated fix
  5. Create single PR for all fixes

Framework-Specific Guidance

SOC 2 Best Practices

  • Enable CloudTrail/Activity Log for all regions
  • Implement MFA for all user accounts
  • Encrypt data at rest and in transit
  • Regular access reviews
  • Incident response procedures

ISO 27001 Best Practices

  • Document security policies
  • Asset inventory maintenance
  • Regular security assessments
  • Change management controls
  • Security awareness training

PCI DSS Best Practices

  • Network segmentation for cardholder data
  • Strong access control measures
  • Regular vulnerability scans
  • Security monitoring and alerting
  • Encryption of card data

Integrations

Continuous Monitoring

Cloudgeni continuously monitors your cloud environments:
  • Real-time finding detection
  • Automatic score updates
  • Alert on compliance changes
  • Drift detection

SIEM Integration

Export findings to your SIEM:
  • JSON export format
  • Webhook notifications
  • API access for automation

Troubleshooting

Score Not Updating:
  • Run a new compliance scan
  • Check cloud account connectivity
  • Verify scan completed successfully
Missing Framework:
  • Check cloud provider support
  • Verify account is connected
  • Some frameworks require specific regions
Report Generation Failed:
  • Check for scan completion
  • Verify data exists for date range
  • Try smaller date range
Findings Not Clearing:
  • Remediation may not be applied yet
  • Run new scan after applying fix
  • Check fix was merged to main branch