Manage IaC compliance - Administrator Guide - Cortex Cloud Posture Management - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-04
Category
Administrator Guide

Manage IaC compliance assessments and reports directly in the tenant to generate and download audit-ready compliance evidence. You can view mapped rules, enforce compliance via policies, and filter issues by specific regulatory controls.

View IaC compliance rules mapped to compliance standards and controls

You can view and modify compliance standards mapped to specific IaC rules in AppSec Rules to control which rules are evaluated for compliance and ensure that findings are correctly attributed to the intended compliance framework.

  1. Navigate to ModulesApplication SecurityAppSec Rules.

  2. Filter the table by IaC -supported Compliance Standards OR Compliance Controls attributes.

    Danger

    Add these properties to the IaC Rules table through the Table Settings Menu, as they are not exposed by default.

Create Cortex Cloud Application Security policies with IaC compliance conditions

Create policies to include or exclude findings based on specific IaC compliance standards and controls. This provides precise control over automated issue creation and build-blocking.

  1. Navigate to ModulesApplication SecurityAppSec PolicesAdd Policy.

  2. Follow the standard procedure in the policy wizard. The configuration for all steps remains the same, except for the Conditions step.

  3. On the Conditions step of the wizard.

    1. Apply a compliance filter: Select either Compliance Standard or Compliance Control as the attribute.

    2. Select the required values for the standard or control.