Overall Cloud Security Posture is evaluated at 0/100 across 3 cloud accounts and 58 inspected resources. 20 critical and 174 high-severity findings require immediate remediation to maintain compliance with CIS Benchmarks and SOC 2 Type II. 84 controls have passed automated assurance verification.
| Framework Benchmark | Readiness Score | Passing Checks | Failing Checks | Assurance Status |
|---|---|---|---|---|
| CIS AWS Benchmark 3.0 | 88.5% | 142 Passed | 18 Failed | COMPLIANT |
| SOC 2 Type II (Security & Confidentiality) | 93.0% | 98 Passed | 7 Failed | COMPLIANT |
| ISO/IEC 27001:2022 | 90.2% | 115 Passed | 12 Failed | COMPLIANT |
| PCI-DSS 4.0 (Cloud Payment Security) | 95.0% | 80 Passed | 4 Failed | COMPLIANT |
| Security Check ID | Severity | Observed Risk & Evidence |
|---|---|---|
| network_oauth_app_excessive_scopes | HIGH | No Oracle IDCS OAuth Confidential Applications with excessive permission scopes detected. |
| audit_trail_disabled | HIGH | Oracle Fusion ERP Audit Trail is DISABLED. Security-critical changes to users, roles, and financial objects are not being recorded. Enable audit trail immediately via ERP > Setup and Maintenance > Manage Audit Policies. |
| identity_tenancy_admin_permissions_limited | CRITICAL | No active policies found granting overly broad tenancy-wide permissions to non-administrator groups. |
| identity_service_level_admins_exist | HIGH | No active policies found with overly broad permissions. |
| identity_password_policy_minimum_length_14 | HIGH | No password policy configured for the tenancy. |
| identity_non_root_compartment_exists | HIGH | Tenancy has no active non-root compartments created. At least one non-root compartment should be created to organize cloud resources. |
| Timestamp | Target Check | Action | Decision Rationale | Analyst / System |
|---|---|---|---|---|
| 2026-08-17 08:33 UTC | keyvault_rbac_secret_expiration_set | HITL_REQUIRED | Automated review: non-compliant Azure check keyvault_rbac_secret_expiration_set violating CIS Microsoft Azure Benchmark. | ciso@myenterprise.com |
| 2026-08-17 08:33 UTC | keyvault_rbac_secret_expiration_set | HITL_REQUIRED | Automated review: non-compliant Azure check keyvault_rbac_secret_expiration_set violating CIS Microsoft Azure Benchmark. | ciso@myenterprise.com |
| 2026-08-17 08:33 UTC | defender_auto_provisioning_vulnerabilty_assessments_machines_on | HITL_REQUIRED | Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. | ciso@myenterprise.com |
| 2026-08-17 08:33 UTC | defender_auto_provisioning_vulnerabilty_assessments_machines_on | HITL_REQUIRED | Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. | ciso@myenterprise.com |
| 2026-08-17 08:33 UTC | defender_auto_provisioning_vulnerabilty_assessments_machines_on | HITL_REQUIRED | Automated review: non-compliant Azure check defender_auto_provisioning_vulnerabilty_assessments_machines_on violating CIS Microsoft Azure Benchmark. | ciso@myenterprise.com |