Skip to main content

Policy Deployment

This guide summarizes how policies move from templates to active controls in your environment.

From Templates to Deployed Policies

Cloudaware ships many controls as policy templates grouped into packs (for example, CIS Benchmarks, foundational security controls). The typical deployment flow is:

  1. Open the Templates Library in Compliance Engine.
  2. Locate the template you want to use (for example, a CIS benchmark or a Cloudaware best‑practice control).
  3. Review and, if needed, adjust scoping and metadata.
  4. Test run the policy against a limited set of objects to validate behavior.
  5. Deploy the policy so it appears in the Policy List and can be evaluated on schedule.

Test runs help you validate scope and logic before you generate findings across your entire environment.

Scoping by Environment and Account

When deploying a policy, you can:

  • Restrict evaluation to specific environments (for example, production only).
  • Limit scope to particular accounts, subscriptions, or projects.
  • Exclude or include resources based on tags, labels, or CMDB attributes.

These scoping decisions are part of the policy definition and should reflect your risk appetite and rollout plan.

Scheduling Evaluations

Once deployed, a policy can be:

  • Scheduled to run at a fixed cadence (for example, hourly, daily, weekly).
  • Executed on demand when you need an immediate refresh of findings.

You can schedule policies individually or in bulk (for example, all CIS benchmark policies for a provider). High‑impact policies that may produce many findings should be scheduled carefully to avoid overwhelming teams with alerts.

See Evaluation Cadence for more guidance.

Safely Rolling Out New Policies

For new or high‑risk controls:

  • Start with a test run or limited scope (for example, a pilot account or application).
  • Review findings with owners to confirm that results match expectations.
  • Gradually expand scope to more environments as confidence grows.

Using this approach, you avoid surprise volumes of violations and can refine controls before they become mandatory.