Skip to main content

Cloud Posture

Cloud Posture turns one read-only connection into continuous compliance. You grant SolveGRC a scoped, read-only view of your AWS, Azure, or GCP account, and it keeps pulling from there: configuration and vulnerability findings, a live asset inventory, topology diagrams, and attack paths, all refreshed automatically. Findings arrive already carrying their compliance-standard references, and once a failing check is mapped to one of your controls, every future finding on that check feeds your frameworks without anyone re-doing the work.

ScreenshotThe Cloud Posture hub: a card per connected cloud showing sync status, asset count, open findings, and control-mapping coverage, with the Connect a cloud and Import findings actions in the header.

The lifecycle at a glance

Posture is a loop, not a project. It runs in five movements:

  1. Connect. Connect a cloud with a read-only role — the AWS wizard is nearly one-click, and no long-lived keys are ever stored.
  2. Sync. The first scan lands in minutes, then every connected cloud re-syncs on its own every 6 hours. A Sync now button exists when you cannot wait.
  3. Review. Findings land in one table — status, severity, the failing resource, and remediation guidance.
  4. Map. Map failing checks to your controls, once per rule, with AI suggestions you approve. Mapped findings satisfy framework controls automatically from then on.
  5. Promote. Assets and attack paths flow into the asset registry, Business Impact Analysis, and the risk register when you decide they should.

How this connects

Cloud Posture consumes exactly one thing: your read-only cloud connections. Out of that single input it produces findings mapped to compliance standards, a live asset inventory, per-VPC topology diagrams, attack paths, and a security change feed. Those outputs feed:

  • Frameworks and controls — mapped findings count toward control and framework satisfaction. See Assess controls.
  • The Asset Registry — every discovered resource lands in the unified registry as one canonical identity.
  • Risks — quantified cloud risks can be sent to the risk register. See Promote from signals.
  • Continuity — assets promoted to BIA carry dependency edges into recovery planning.
This runs on a schedule

Connected clouds sync every 6 hours without anyone pressing a button, findings carry their framework references automatically, and you can opt in to email alerts when a new high-risk attack path appears. Cadence, not calendar reminders, is what keeps the picture current.

Before you start

The connect wizard tells you what it needs as you go, but it helps to arrive with the right access:

  • AWS. You need permission to create IAM roles in the account, and Security Hub must be enabled in the region you pick, with a standard turned on (CIS or FSBP) — otherwise there are no findings to pull. Enabling AWS Resource Explorer is recommended so your full systems inventory syncs; without it, only tagged resources are inventoried.
  • Azure. You need to create an app registration and grant it Security Reader on the subscription (for findings) plus Reader (for the systems inventory).
  • GCP. You need to create a service account with Security Center Findings Viewer plus Cloud Asset Viewer and download its JSON key.
No live access yet?

You can still use the module. Import findings accepts scan exports from Prowler (native or OCSF), AWS Security Hub (ASFF), and ScoutSuite, plus a simple normalized JSON format, and the same mapping and review flow applies. Connect live later and the two paths land in the same place.

Start with Connect a cloud.