Skip to content

Features of CSPM

Last updated on

The STACKIT Portal provides a dedicated, intuitive User Interface for CSPM. Once the service is enabled, you can utilize the dashboard to check the following aspects of your project:

  • Overall Compliance Status: Instantly view a high-level summary of your project’s security health. The dashboard visualizes your compliance percentage, shows a breakdown of compliant versus violated policies, and plots your compliance trend over the last 30 days.
  • Benchmark Filtering: The CSPM compliance dashboard allows you to filter for security benchmarks in the monitored policy violations, by selecting the benchmark you want to assess (e.g., BSI C5 Basic or the internal STACKIT Standard).
  • Top 5 Violated Policies: Review a prioritized list of the most frequent security gaps in your project (e.g., missing TLS encryption, public object storage buckets), complete with the exact number of occurrences.
  • Detailed Policy View & Affected Resources: Click on any specific policy violation to reveal the dedicated violating resources table. Here, you can identify the exact STACKIT assets (e.g., PROD-LB-gateway), their severity level (e.g., High), and when the violation was last detected.
  • Mitigation Guidance: By selecting a policy from the “Monitored policy violations” list, you can access the detailed policy description. This description includes the mitigation guide, providing helpful hints and instructions to help engineers fix the broken resource quickly.
  • Report Generation: Use the “Export CSV” button in the top right corner of the dashboard to download point-in-time compliance reports for auditor or stakeholder reviews.