Skip to main content

Compliance and Security Audit

Compliance and Security Audit turns scan results into framework-level posture. Open Security > Compliance to review scores, failing controls, and related findings.

What it does

  • Calculates framework scores from scan results.
  • Shows control-level pass and fail status.
  • Links failing controls back to affected findings and resources.
  • Helps teams distinguish operational triage from accepted risk.

Requirements

  • At least one connected and scanned cloud account.
  • Active compliance frameworks configured in Settings > General when your organization wants to focus reporting on specific frameworks.

No DevOps Genie Agent is required.

Finding state impact

Finding stateCompliance impact
OpenFailing when tied to a control.
AcknowledgedStill failing. Acknowledgment means reviewed, not accepted.
Accepted riskTreated as an accepted exception while active.
ResolvedNo longer active after scanning.
  1. Open Security > Compliance.
  2. Start with the lowest-scoring framework.
  3. Open failing controls.
  4. Review related findings.
  5. Fix, acknowledge, or accept risk based on your process.
  6. Re-scan to confirm changes.