Documentation Index

Fetch the complete documentation index at: https://docs.senhasegura.io/llms.txt

Use this file to discover all available pages before exploring further.

Compliance

Prev Next

This document provides information about the Compliance report screen. This screen shows information about the accounts assessed, the total exceptions applied, frameworks, resources and more information related to Cloud Entitlements’s compliance.

The platform supports specialized reporting categories, including privileged access controls, audit evidence gathering, strict segregation-of-duties (SoD) checks, and exception tracking. Additionally, administrators can build custom frameworks by mapping and combining individual controls from existing market frameworks supported by the system.

Compliance reports can be scheduled for automatic execution at defined intervals. These scheduled reports can be exported in .pdf and .csv formats via email, or distributed through Cloud Entitlements’ integration with Slack.

Path to access

  1. Access the Cloud Security platform.
  2. Access the Cloud Entitlements product.
  3. In the Cloud Entitlements menu, click Compliance.

Within the report, you'll find the following information:

Cards

Item Description
Total accounts assessed The total amount of accounts assessed by Cloud Entitlements’s compliance.
Total exceptions applied The total amount of exceptions applied to Cloud Entitlements’s accounts.

Graphics

Item Description
Frameworks A chart containing all frameworks and its resources. See the following frameworks accepted in Cloud Entitlements:
- Sensitive data and privacy: GDPR (European data protection), LGPD (Brazilian data protection), HIPAA (US healthcare), FFIEC.
- Regulatory compliance and governance: PCI DSS (Payment Card Industry), SOX (Sarbanes-Oxley), FedRAMP, RBI, DORA (EU operational resilience), NIS2 (EU).
- Industry standards and best practices: CIS Benchmarks, NIST 800-series (including NIST 800-53), NIST Cybersecurity Framework (CSF), ISO 27001 / ISO 27002, CISA.
- Organizational governance and quality control: SOC 2 (Type I and Type II), GXP, ENS (Spanish National Security Scheme), Saudi Arabia Vision 2030 / NCA ECC.
- Cloud-specific frameworks: AWS Foundational Technical Review (FTR), AWS Well-Architected Framework (Security Pillar).
Resources A chart containing the status of the framework’s resources.

Report fields

Item Description
Account ID Account’s ID.
Name Account’s name.
Connected at Account’s connection date.
Score Account’s compliance score.
Framework Account’s framework.
Export Button to export the Compliance report. Supports native export in .pdf (for formal audit submissions) and .csv (for deeper data analysis). Deliveries can be routed via email or Slack integration.