CIS基准云审计

原名:auditing-cloud-with-cis-benchmarks

通过 Prowler 和 ScoutSuite 等工具对 AWS、Azure 和 GCP 环境运行自动化扫描,对照 CIS 基础基准审计,解读失败的控制项并跟踪修复,实现持续合规。适用于云安全审计、CIS 基准合规验证及持续云合规监控。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-21
TRACE 评分
3.6 / 5

内容概览

- When performing initial security audits of cloud environments against industry-standard benchmarks - When preparing for SOC 2, ISO 27001, or regulatory audits that reference CIS controls - When establishing a measurable security baseline for new cloud accounts or subscriptions - When tracking compliance improvement over time with periodic reassessment - When evaluating the security posture of acquired or inherited cloud environments Do not use for runtime threat detection (see detecting-cloud-threats-with-guardduty), for application-level security testing (see conducting-cloud-penetration-testing), or for compliance frameworks not based on CIS (refer to specific regulatory skill files). - Read-only access to target cloud accounts (AWS SecurityAudit policy, Azure Reader role, GCP Viewer role) - Prowler, ScoutSuite, or cloud-native CSPM tools installed and configured - Understanding of C…

查看 SKILL 详情