Skip to main content

Security & Compliance Analysts Quick Start

Use this guide to start a Cloudaware security and compliance rollout. It focuses on the minimum sequence needed to establish CMDB-backed policy scope, triage findings, route remediation, handle exceptions, and produce audit-ready evidence.

Before You Start

Confirm that you have:

  • Access to a Cloudaware account, CMDB views, and security modules you will use.
  • Agreement on the first compliance frameworks, policy packs, controls, or internal standards to monitor.
  • A list of in-scope accounts, subscriptions, projects, tenancies, clusters, applications, and environments.
  • Named control owners, remediation owners, risk owners, and approvers for exceptions.
  • Required integrations for cloud inventory, identity, vulnerability data, endpoint data, ticketing, and notifications.
  • A reporting cadence for posture reviews, audit evidence, and remediation follow-up.

Confirm CMDB Scope

Security and compliance workflows depend on complete CMDB context. Before reviewing findings, confirm that the target environments are connected, current, and mapped to owners.

Start with:

Validate ownership, environment, application, criticality, exposure, and compliance-boundary metadata before using findings for formal reporting.

Enable Compliance & Security Baselines

Start with a narrow policy baseline that maps to a known scope and ownership model. Expand after findings are trustworthy and remediation routing is working.

Use:

For the first rollout, separate production and non-production findings so control owners can prioritize risk accurately.

Triage Findings

Create a repeatable triage process before assigning remediation at scale.

Check each finding for:

  • Affected asset, owner, application, environment, and business context.
  • Policy, control, benchmark, severity, and evidence.
  • Current state, first seen date, last seen date, and recurrence.
  • Existing exception, duplicate ticket, or accepted risk.
  • Remediation owner and expected service impact.

Use Compliance Engine, CMDB CI Detail Layout, Change Events, and History & Audit during triage.

Route Remediation

Route findings to the teams that can act, and keep Cloudaware as the shared context for ownership, status, and evidence.

Use:

Define escalation rules for critical findings, internet-exposed assets, production systems, regulated workloads, and overdue remediation.

Manage Exceptions And Risk Acceptance

Not every finding can be remediated immediately. Define exception rules so accepted risks are visible, time-bound, and auditable.

For each exception, capture:

  • The asset, policy, control, and business justification.
  • Compensating controls or monitoring requirements.
  • Risk owner and approval authority.
  • Expiration date and review cadence.
  • Evidence needed to revisit the decision.

Use Compliance Engine, Audit Access, and History & Audit to support review processes.

Add Security Data Sources

Enrich CMDB and findings with security, vulnerability, endpoint, and detection sources.

Common starting points:

Use ownership and environment metadata from CMDB to prioritize vulnerability and detection work.

Publish Security And Audit Views

Create the first reports around questions stakeholders already ask:

  • Which controls are failing by framework, cloud, application, environment, or owner?
  • Which critical findings are new, recurring, overdue, or unassigned?
  • Which production or internet-exposed assets have unresolved high-risk findings?
  • Which exceptions are active, expiring, or missing approvals?
  • What evidence supports the latest audit period?

Use Compliance Engine, CMDB Queries & Reporting, Advanced Analytics, and Report & Dashboard Gallery.

Next Steps