CIS基准云审计
原名:auditing-cloud-with-cis-benchmarks
通过 Prowler 和 ScoutSuite 等工具对 AWS、Azure 和 GCP 环境运行自动化扫描,对照 CIS 基础基准审计,解读失败的控制项并跟踪修复,实现持续合规。适用于云安全审计、CIS 基准合规验证及持续云合规监控。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3.6 / 5
内容概览
- When performing initial security audits of cloud environments against industry-standard benchmarks - When preparing for SOC 2, ISO 27001, or regulatory audits that reference CIS controls - When establishing a measurable security baseline for new cloud accounts or subscriptions - When tracking compliance improvement over time with periodic reassessment - When evaluating the security posture of acquired or inherited cloud environments Do not use for runtime threat detection (see detecting-cloud-threats-with-guardduty), for application-level security testing (see conducting-cloud-penetration-testing), or for compliance frameworks not based on CIS (refer to specific regulatory skill files). - Read-only access to target cloud accounts (AWS SecurityAudit policy, Azure Reader role, GCP Viewer role) - Prowler, ScoutSuite, or cloud-native CSPM tools installed and configured - Understanding of C…