Skip to content

Concepts

Last updated on

  • Project-Level Security Dashboard: The service currently provides a single, unified view of security risks and compliance status at the project level via the STACKIT Portal UI. Future iterations will expand this to include hierarchical views at the folder and organization levels.
  • Compliance Assessment: Continuous compliance assessment against both public industry standards (like BSI C5 and ISO 27000) and the internal STACKIT Standard.
  • Automated Detection & Mitigation: Automated detection of misconfigurations and vulnerabilities, complete with guided mitigation recommendations directly in the interface.
  • Compliance Report Export: Generate and export point-in-time compliance snapshots directly from the UI. This allows you to generate tamper-evident compliance state logs to easily share your security posture and audit readiness with stakeholders.

To scan and assess your resources seamlessly, STACKIT CSPM automatically provides a dedicated service account within your project.

  • Account Format: harvester-*@cspm.sa.stackit.cloud
  • Deployment: Created exactly once per customer project upon service activation.
  • Purpose: The Data Harvester securely scans your IaaS resources (e.g., Kubernetes clusters) from your project and validates them against the security policies.
  • Security: To ensure the highest level of security, this account strictly utilizes short-lived tokens.
  • Comprehensive transparency: You gain complete transparency into your cloud security, helping you spot potential risks and reduce the chance of security incidents.
  • Reduced attack surface: You can actively prevent security breaches and reduce your overall attack surface with faster detection and clear, guided steps to mitigate identified risks.
  • Simplified auditing: You can simplify compliance management and cut down on manual effort for audits, ensuring your operations align with important regulations like BSI C5 and ISO 27000.