Your accounts assessed against the CIS Benchmark, read-only, with the failures that matter ranked ahead of the ones that do not.
Each control needs evidence gathered from a different service, and the picture changes every time someone deploys.
The IT Operations Engine gathers that evidence read-only, scores every control, and tells you which failures matter most.
What a benchmark report has to do
The engine assesses each account against the CIS Benchmark for the cloud in question and reports each control with its evidence. Failures carry a remediation path, executed under your authority model where it is a configuration change and raised as a pull request where it touches code.
Want the benchmark report before anything changes?
Three accounts, one benchmark, read-only. Enough to judge the shape of it.
Enough to show the shape of the report before it runs estate-wide.
You choose which benchmark version and level you adopt. The engine assesses against the version you name.
Three accounts assessed across identity and access, logging, monitoring, networking and storage. Each control returns a pass or a fail with its evidence.
Configuration fixes run under your authority model, code fixes arrive as pull requests, and an approved fix can be promoted to a standing action.
The engine assesses against the version you name. We recommend the current release.
You gain:
FAQ
AWS today, with Azure and Google Cloud benchmarks following the same pattern.