New Savings Proposals: approve, test and roll back cost changesLearn more Sign in|Talk to a cloud engineer

Compliance scores backed by live evidence

Atlas maps its detections to SOX IT General Controls, CIS AWS Foundations, CIS Kubernetes, PCI DSS and the HIPAA Security Rule. Each control links to the resources behind it. If the evidence can't be collected, the control reads Not assessed, never passed.

What you're watching
  1. 1
    Scan the five framework cards

    SOX ITGC, CIS AWS, CIS Kubernetes, PCI DSS and HIPAA each show passed, failed and not assessed. Not assessed never adds to the pass count.

  2. 2
    Open SOX ITGC

    84%, with 21 passed, 4 failed and 1 not assessed, split across the four control domains.

  3. 3
    Read the controls needing attention

    ci-deployer's key is 212 days old, CloudTrail log file validation is off, and ITGC-CO-04 is blocked by a missing backup:ListBackupJobs permission.

  4. 4
    Export the report as PDF

    The PDF carries controls, evidence and linked findings, ready for the audit walkthrough.

Who does thisGRC lead, with the security engineering leadWhat you getA SOX ITGC report built from the latest scan, with every failure tied to a named resource and owner.
0
frameworks scored from live detections
0
SOX ITGC control domains
0
export formats: CSV, PDF and JSON
0
controls not assessed at Lumora Retail, shown separately (sample data)

Audit evidence gets collected the week before the audit

Screenshots and spreadsheets go stale the day after they are taken. These are the usual failure points.

Audit

Audit prep is manual

What usually happens: Two weeks before the SOX walkthrough, someone collects console screenshots and hopes nothing changed since.

How CloudLens resolves it: Each control links to current evidence and the findings behind any failure, exportable as PDF, CSV or JSON.

Resolved
Accuracy

Missing access inflates scores

What usually happens: A control that couldn't be evaluated is dropped from the calculation, and the percentage goes up.

How CloudLens resolves it: Not assessed appears on every framework card, is never counted as a pass, and names the permission that would fix it.

Resolved
Ownership

Failed controls have no owner

What usually happens: A spreadsheet row says the S3 encryption control failed, with no resource named and no ticket.

How CloudLens resolves it: Open the control, see the exact resources, and send the finding to Jira from the same page.

Resolved

A quarterly SOX ITGC review in five steps

Lena runs the quarterly SOX ITGC review with Lumora Retail's external auditors.

LPLena ParkGRC lead, Lumora Retail

Lumora Retail is a fictional company. The people, names and numbers are sample data.

    1
    Mon 09:00

    Opens the SOX ITGC card

    84%: 21 controls passed, 4 failed, 1 not assessed. She starts with Access to Programs and Data, where most of the failures are.
    2
    Mon 09:30SEC-77

    Drills into a failed control

    The evidence is a long-lived access key on ci-deployer with no MFA. The linked finding already has SEC-77 attached, so there is an owner and a date.
    3
    Mon 10:10Not assessed

    Looks at the not-assessed control

    It's blocked by a missing read permission on the scan role. The page shows the permission and a policy snippet, and the platform team adds it to the StackSet.
    4
    Tue 07:00

    The next scan assesses it

    The control now has a result based on real evidence. The score moved because evidence arrived, not because a row was removed.
    5
    Thu 14:00

    Exports for the auditors

    A PDF for the walkthrough meeting, and a CSV of controls, results and linked findings for the auditors' workpapers.
Audit coming up?

Walk in with evidence, not screenshots

Five frameworks, one set of evidence

Sample scores for a fictional company. Not assessed is shown on every card and never added to the pass count.

SOX ITGC
SOX IT General Controls
84%

IT general controls for systems that support financial reporting.

Access to Programs and DataProgram ChangesComputer OperationsData Integrity
21 passed4 failed1 not assessed
CIS AWS
CIS AWS Foundations Benchmark
78%

Identity, storage, logging, monitoring and networking configuration.

IAMLoggingNetworking
39 passed11 failed0 not assessed
CIS K8s
CIS Kubernetes Benchmark
69%

Pod security, RBAC and cluster configuration on EKS.

PodsRBACCluster
58 passed26 failed3 not assessed
PCI DSS
PCI DSS
72%

Safeguards for cardholder data. Depends on data classification.

Needs classification
44 passed17 failed2 not assessed
HIPAA
HIPAA Security Rule
81%

Safeguards for protected health information. Depends on data classification.

Needs classification
30 passed7 failed0 not assessed

From control to evidence to the fix

Toxic combinations and findings
Open a failed control to see the resources behind it, then jump to the finding with its severity, triage state and remediation steps. Send it to Jira without leaving the page. The evidence names each user or resource that failed and when the control was last evaluated.
  • Open the failed control
  • See the users or resources behind it
  • Jump to the finding
  • Create the Jira issue
What you're watching
  1. 1
    Open the failed CIS AWS control

    The MFA control for IAM users with a console password has failed. It was evaluated 2 hours ago against 3 users.

  2. 2
    Look at the evidence

    j.rivera and m.chen have console passwords without MFA. ci-deployer has no MFA and an access key 212 days old.

  3. 3
    Send the finding to Jira

    ci-deployer's finding opens with its severity and triage state. Create Jira issue makes SEC-77 and moves triage to In Progress.

Who does thisGRC analyst, handing off to the IAM or platform ownerWhat you getA failed control with named users and a ticket, ready for the auditor's follow-up question.

Blocked checks name the permission to grant

Security and trust
If the scan role can't read something, the affected controls read Not assessed and list the read permission they need. Add it to the role and the next scan assesses those controls.
  • Missing permission listed
  • Not assessed is not passed
  • Read-only policy snippet
What you're watching
  1. 1
    See which checks aren't running

    Four checks across PCI DSS, CIS AWS, CIS Kubernetes and SOX ITGC read Not assessed. Each row names its missing permission, such as macie2:ListFindings.

  2. 2
    Show the policy

    Atlas writes one read-only policy statement with the four List and Describe actions.

  3. 3
    Copy it to the scan role

    Add it to the CloudLens read-only role, and the next scan assesses those controls with real evidence.

Who does thisCloud security engineer, with the team that manages the scan role StackSetWhat you getFour blocked controls become one policy change you can copy and paste.

Reports for auditors and for pipelines

Export controls, results and linked findings as PDF for review meetings, CSV for spreadsheets, or JSON for data pipelines and SIEM ingestion. Every export comes from the latest scan, and not-assessed controls appear as their own result.
  • PDF for review meetings
  • CSV for auditor workpapers
  • JSON for pipelines and SIEM
What you're watching
  1. 1
    PDF for the review meeting

    The SOX ITGC control report shows 84%, the passed, failed and not assessed counts, and each control's result.

  2. 2
    CSV for the workpapers

    One row per control with its id, title, result and evidence count, ready for the auditors' spreadsheet.

  3. 3
    JSON for pipelines

    The same score and control results as structured data, for a data pipeline or SIEM ingestion.

Who does thisGRC lead preparing audit evidenceWhat you getOne report from the latest scan in three formats, so nobody retypes results into a spreadsheet.

Scores that change when the estate changes

Exports

CSV, PDF and JSON exports of controls, evidence and findings.

Multi-account rollup

Each account shows Current, Partly read, Out of date or Never scanned. An unscanned account never ranks as the cleanest.

Per-org policies

Tag, scan and issue policies set required tags, what gets scanned and what counts as work.

Triage and Jira

Acknowledge, snooze or ticket failed controls. Jira status is shown next to the finding.

Compliance questions

SOX IT General Controls, CIS AWS Foundations Benchmark, CIS Kubernetes Benchmark, PCI DSS and the HIPAA Security Rule.

Atlas couldn't collect the evidence a control needs, usually because of a missing read permission or data that hasn't been classified. Those controls are listed separately and never counted as passed.

Every time Atlas scans, on the intervals set in your scan policy.

Yes. Kubernetes checks run against EKS clusters and need an EKS access entry for the CloudLens role.

Yes. Export any framework as PDF, CSV or JSON, including the evidence and linked findings behind each control.

Go into your next audit with evidence

Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.