This document provides information about the Compliance report screen. This screen shows information about the accounts assessed, the total exceptions applied, frameworks, resources and more information related to Cloud Entitlements’s compliance.
The platform supports specialized reporting categories, including privileged access controls, audit evidence gathering, strict segregation-of-duties (SoD) checks, and exception tracking. Additionally, administrators can build custom frameworks by mapping and combining individual controls from existing market frameworks supported by the system.
Compliance reports can be scheduled for automatic execution at defined intervals. These scheduled reports can be exported in .pdf and .csv formats via email, or distributed through Cloud Entitlements’ integration with Slack.
Path to access
- Access the Cloud Security platform.
- Access the Cloud Entitlements product.
- In the Cloud Entitlements menu, click Compliance.
Within the report, you'll find the following information:
Cards
| Item | Description |
|---|---|
| Total accounts assessed | The total amount of accounts assessed by Cloud Entitlements’s compliance. |
| Total exceptions applied | The total amount of exceptions applied to Cloud Entitlements’s accounts. |
Graphics
| Item | Description |
|---|---|
| Frameworks | A chart containing all frameworks and its resources. See the following frameworks accepted in Cloud Entitlements: - Sensitive data and privacy: GDPR (European data protection), LGPD (Brazilian data protection), HIPAA (US healthcare), FFIEC. - Regulatory compliance and governance: PCI DSS (Payment Card Industry), SOX (Sarbanes-Oxley), FedRAMP, RBI, DORA (EU operational resilience), NIS2 (EU). - Industry standards and best practices: CIS Benchmarks, NIST 800-series (including NIST 800-53), NIST Cybersecurity Framework (CSF), ISO 27001 / ISO 27002, CISA. - Organizational governance and quality control: SOC 2 (Type I and Type II), GXP, ENS (Spanish National Security Scheme), Saudi Arabia Vision 2030 / NCA ECC. - Cloud-specific frameworks: AWS Foundational Technical Review (FTR), AWS Well-Architected Framework (Security Pillar). |
| Resources | A chart containing the status of the framework’s resources. |
Report fields
| Item | Description |
|---|---|
| Account ID | Account’s ID. |
| Name | Account’s name. |
| Connected at | Account’s connection date. |
| Score | Account’s compliance score. |
| Framework | Account’s framework. |
| Export | Button to export the Compliance report. Supports native export in .pdf (for formal audit submissions) and .csv (for deeper data analysis). Deliveries can be routed via email or Slack integration. |