Compliance scores backed by live evidence
Atlas maps its detections to SOX IT General Controls, CIS AWS Foundations, CIS Kubernetes, PCI DSS and the HIPAA Security Rule. Each control links to the resources behind it. If the evidence can't be collected, the control reads Not assessed, never passed.
- 1Scan the five framework cards
SOX ITGC, CIS AWS, CIS Kubernetes, PCI DSS and HIPAA each show passed, failed and not assessed. Not assessed never adds to the pass count.
- 2Open SOX ITGC
84%, with 21 passed, 4 failed and 1 not assessed, split across the four control domains.
- 3Read the controls needing attention
ci-deployer's key is 212 days old, CloudTrail log file validation is off, and ITGC-CO-04 is blocked by a missing backup:ListBackupJobs permission.
- 4Export the report as PDF
The PDF carries controls, evidence and linked findings, ready for the audit walkthrough.
Audit evidence gets collected the week before the audit
Screenshots and spreadsheets go stale the day after they are taken. These are the usual failure points.
Audit prep is manual
What usually happens: Two weeks before the SOX walkthrough, someone collects console screenshots and hopes nothing changed since.
How CloudLens resolves it: Each control links to current evidence and the findings behind any failure, exportable as PDF, CSV or JSON.
ResolvedMissing access inflates scores
What usually happens: A control that couldn't be evaluated is dropped from the calculation, and the percentage goes up.
How CloudLens resolves it: Not assessed appears on every framework card, is never counted as a pass, and names the permission that would fix it.
ResolvedFailed controls have no owner
What usually happens: A spreadsheet row says the S3 encryption control failed, with no resource named and no ticket.
How CloudLens resolves it: Open the control, see the exact resources, and send the finding to Jira from the same page.
ResolvedA quarterly SOX ITGC review in five steps
Lena runs the quarterly SOX ITGC review with Lumora Retail's external auditors.
Lumora Retail is a fictional company. The people, names and numbers are sample data.
Opens the SOX ITGC card
Drills into a failed control
Looks at the not-assessed control
The next scan assesses it
Exports for the auditors
Walk in with evidence, not screenshots
Five frameworks, one set of evidence
Sample scores for a fictional company. Not assessed is shown on every card and never added to the pass count.
IT general controls for systems that support financial reporting.
Identity, storage, logging, monitoring and networking configuration.
Pod security, RBAC and cluster configuration on EKS.
Safeguards for cardholder data. Depends on data classification.
Safeguards for protected health information. Depends on data classification.
- Open the failed control
- See the users or resources behind it
- Jump to the finding
- Create the Jira issue
- 1Open the failed CIS AWS control
The MFA control for IAM users with a console password has failed. It was evaluated 2 hours ago against 3 users.
- 2Look at the evidence
j.rivera and m.chen have console passwords without MFA. ci-deployer has no MFA and an access key 212 days old.
- 3Send the finding to Jira
ci-deployer's finding opens with its severity and triage state. Create Jira issue makes SEC-77 and moves triage to In Progress.
- Missing permission listed
- Not assessed is not passed
- Read-only policy snippet
- 1See which checks aren't running
Four checks across PCI DSS, CIS AWS, CIS Kubernetes and SOX ITGC read Not assessed. Each row names its missing permission, such as macie2:ListFindings.
- 2Show the policy
Atlas writes one read-only policy statement with the four List and Describe actions.
- 3Copy it to the scan role
Add it to the CloudLens read-only role, and the next scan assesses those controls with real evidence.
Reports for auditors and for pipelines
- PDF for review meetings
- CSV for auditor workpapers
- JSON for pipelines and SIEM
- 1PDF for the review meeting
The SOX ITGC control report shows 84%, the passed, failed and not assessed counts, and each control's result.
- 2CSV for the workpapers
One row per control with its id, title, result and evidence count, ready for the auditors' spreadsheet.
- 3JSON for pipelines
The same score and control results as structured data, for a data pipeline or SIEM ingestion.
Scores that change when the estate changes
Exports
CSV, PDF and JSON exports of controls, evidence and findings.
Multi-account rollup
Each account shows Current, Partly read, Out of date or Never scanned. An unscanned account never ranks as the cleanest.
Per-org policies
Tag, scan and issue policies set required tags, what gets scanned and what counts as work.
Triage and Jira
Acknowledge, snooze or ticket failed controls. Jira status is shown next to the finding.
Compliance questions
SOX IT General Controls, CIS AWS Foundations Benchmark, CIS Kubernetes Benchmark, PCI DSS and the HIPAA Security Rule.
Atlas couldn't collect the evidence a control needs, usually because of a missing read permission or data that hasn't been classified. Those controls are listed separately and never counted as passed.
Every time Atlas scans, on the intervals set in your scan policy.
Yes. Kubernetes checks run against EKS clusters and need an EKS access entry for the CloudLens role.
Yes. Export any framework as PDF, CSV or JSON, including the evidence and linked findings behind each control.
Go into your next audit with evidence
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
