RPT-20260822-3e59a
Generated: August 22, 2026 - 14:30:59 UTC

Executive CISO Posture Rating

Overall Cloud Security Posture is evaluated at 0/100 across 3 cloud accounts and 58 inspected resources. 20 critical and 174 high-severity findings require immediate remediation to maintain compliance with CIS Benchmarks and SOC 2 Type II. 84 controls have passed automated assurance verification.

0
Cloud Accounts
3
Critical Findings
20
High Findings
174
Passed Controls
84
1. Regulatory & Compliance Scorecard
Framework Benchmark Readiness Score Passing Checks Failing Checks Assurance Status
CIS AWS Benchmark 3.0 88.5% 142 Passed 18 Failed COMPLIANT
SOC 2 Type II (Security & Confidentiality) 93.0% 98 Passed 7 Failed COMPLIANT
ISO/IEC 27001:2022 90.2% 115 Passed 12 Failed COMPLIANT
PCI-DSS 4.0 (Cloud Payment Security) 95.0% 80 Passed 4 Failed COMPLIANT
2. Critical Threat Vectors Requiring Triage
Security Check ID Severity Observed Risk & Evidence
network_oauth_app_excessive_scopes HIGH No Oracle IDCS OAuth Confidential Applications with excessive permission scopes detected.
audit_trail_disabled HIGH Oracle Fusion ERP Audit Trail is DISABLED. Security-critical changes to users, roles, and financial objects are not being recorded. Enable audit trail immediately via ERP > Setup and Maintenance > Manage Audit Policies.
identity_tenancy_admin_permissions_limited CRITICAL No active policies found granting overly broad tenancy-wide permissions to non-administrator groups.
identity_service_level_admins_exist HIGH No active policies found with overly broad permissions.
identity_password_policy_minimum_length_14 HIGH No password policy configured for the tenancy.
identity_non_root_compartment_exists HIGH Tenancy has no active non-root compartments created. At least one non-root compartment should be created to organize cloud resources.
3. Decision Log & Remediation Trail
Timestamp Target Check Action Decision Rationale Analyst / System
2026-08-17 08:33 UTC keyvault_rbac_secret_expiration_set HITL_REQUIRED Automated review: non-compliant Azure check keyvault_rbac_secret_expiration_set violating CIS Microsoft Azure Benchmark. ciso@myenterprise.com
2026-08-17 08:33 UTC keyvault_rbac_secret_expiration_set HITL_REQUIRED Automated review: non-compliant Azure check keyvault_rbac_secret_expiration_set violating CIS Microsoft Azure Benchmark. ciso@myenterprise.com
2026-08-17 08:33 UTC defender_auto_provisioning_vulnerabilty_assessments_machines_on HITL_REQUIRED Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. ciso@myenterprise.com
2026-08-17 08:33 UTC defender_auto_provisioning_vulnerabilty_assessments_machines_on HITL_REQUIRED Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. ciso@myenterprise.com
2026-08-17 08:33 UTC defender_auto_provisioning_vulnerabilty_assessments_machines_on HITL_REQUIRED Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. ciso@myenterprise.com