Skip to main content

Scoping & Targeting

Scoping determines which assets each policy evaluates. Good scoping keeps findings relevant and manageable.

Dimensions of Scope

When defining a policy, you can target assets based on:

  • Environment – for example, production vs. non‑production.
  • Account/subscription/project – specific cloud accounts or groupings.
  • Region or location – cloud regions or data centers where the policy applies.
  • Tags and labels – application, team, data classification, or other fields.
  • CMDB attributes – any other fields exposed on the target CMDB class.

These dimensions can be combined so that controls align with how your organization models services and risk.

Patterns

Common scoping patterns include:

  • “Apply this control to all production accounts.”
  • “Apply this control to all objects with a critical data classification.”
  • “Exclude sandbox and lab environments from this control.”
  • “Scope this CIS benchmark pack to a small pilot before rolling out widely.”

You can express these patterns in the policy’s query and filters.

Scope Changes and Findings

When an asset moves in or out of scope:

  • If it enters scope, a new finding is created on the next evaluation run.
  • If it leaves scope (for example, account de‑scoped, resource deleted, environment tag changed), the finding is closed and marked as out of scope.

Closed findings retain history for reporting but no longer count against current posture. See Status Transitions for more details.