Skip to content

FAQ

Last updated on

We want to give our customers the information they need to get the most from our STACKIT CSPM. This FAQ section answers common questions. This helps you quickly find solutions and improve your experience. We encourage you to check these FAQ before contacting our support team, as you might find your answer here.

  • General information

    What is STACKIT Cloud Security Posture Management (CSPM)?

    The STACKIT Cloud Security Posture Management service provides proactive control over cloud security. As a native, integrated solution, it delivers comprehensive visibility across the STACKIT cloud ecosystem and automatically detects misconfigurations and vulnerabilities.

    Will the service cover my entire organization?

    Currently, the release focuses on providing visibility and compliance tracking at the project level. The capability to view security posture dashboards and aggregate findings at the folder and organization levels is planned for future iterations.

    Why is my compliance dashboard completely empty?

    If your dashboard is empty, it is highly likely that the harvester-*@cspm.sa.stackit.cloud service account deployed in your project has been disabled. This account is necessary to harvest resource data. To fix this, you must re-enable the CSPM service to recreate the account.

    What are the key benefits?

    You gain complete transparency into your cloud security, helping you spot potential risks and reduce the chance of security incidents. You can actively prevent security breaches and reduce your overall attack surface with faster detection and clear, guided steps to mitigate identified risks.

    How does it help with compliance?

    By checking against both public industry standards and internal STACKIT policies, the Cloud Security Posture Management service simplifies compliance management. It significantly reduces the manual effort required for audits and provides confidence that operations align with important regulations such as BSI C5 and ISO 27000. Additionally, users can export compliance reports via CSV from the UI to share directly with stakeholders.

    Does the service include alerting?

    No, active monitoring and alerting functionalities for policies are not currently available.

    Who is STACKIT CSPM for?

    It is designed for Security & Compliance Officers (for enterprise-grade governance), Project Owners & IT Managers (for specific project health), and DevOps/DevSecOps Engineers (to securely build and fix issues early in the workflow).

    Is agent installation required?

    No, the service operates as a natively integrated capability within STACKIT, negating the need for manual agent installations on your infrastructure. There are no customer-managed versions or infrastructure deployments required.

    What does the compliance percentage (e.g., 85% for BSI C5) in the CSPM dashboard actually mean?

    The percentage represents your compliance rate specifically for the technically verifiable controls that our Cloud Security Posture Management (CSPM) tool can automatically monitor. It shows the proportion of CSPM-evaluable controls that are currently passing versus failing in your cloud environment.

    Does an 85% score mean that 85% of the entire standard is compliant?

    No. It is a common misconception that this number reflects the entire framework. Compliance frameworks like BSI C5, SOC 2, or ISO 27001 consist of both technical and non-technical controls. Your score only reflects the controls the CSPM is capable of assessing.

    Why can't the CSPM check all the controls in a framework?

    CSPM works by scanning your cloud infrastructure’s APIs and configurations (e.g., checking if databases are encrypted or if MFA is enforced). However, they cannot verify organizational, process-based, or physical controls. For example, the CSPM cannot check:

    • Human Resources (HR) controls (e.g., employee background checks or onboarding processes).
    • Physical security (e.g., badge access to a physical office or server room).
    • Administrative processes (e.g., whether employees have completed their annual security awareness training).

    How often is my project scanned?

    Currently the products are scanned every 24 h.