Updated built-in compliance standards - Cortex XSIAM

Cortex XSIAM 3.x Release Notes

Product
Cortex XSIAM
Last date published
2026-06-09

The underlying rules were updated for the some standards:

Updates to compliance standards may affect assessment results.

Change summary Details

Mapped AI-focused cloud security posture management rules to all existing AI standards

Appended new AI-related configuration rules to the existing standards to strengthen the governance and management of AI systems.

This provides a more comprehensive assessment of AI risk management practices, ensuring alignment with international safety and ethical standards.

The following standards were updated:

  • EU AI Act
  • ISO/IEC 42001:2023
  • NIST AI 600-1
  • OWASP Top 10 for LLM Applications 2025
  • OWASP Top 10 for Agentic Applications 2026

Mapped Kubernetes security posture management rules to the existing cloud workload protection standards

Introduced our first set of KSPM-specific security configuration rules and enabled rule mapping on existing benchmarks.

This empowers organizations to identify and remediate Kubernetes misconfigurations for the first time, establishing a baseline for foundational security hygiene.

The following standards were updated:

  • CIS Amazon Elastic Kubernetes Service (EKS) Benchmark v1.4
  • CIS Amazon Elastic Kubernetes Service (EKS) Benchmark v1.7
  • CIS Azure Kubernetes Service (AKS) Benchmark v1.5
  • CIS Azure Kubernetes Service (AKS) Benchmark v1.8
  • CIS Docker Benchmark v1.7.0
  • CIS Google Kubernetes Engine (GKE) Benchmark v1.6
  • CIS Google Kubernetes Engine (GKE) Benchmark v1.8
  • CIS Kubernetes Benchmark v1.11.0
  • CIS Red Hat OpenShift Container Platform v1.7.0
  • Health Insurance Portability and Accountability Act (HIPAA)
  • PCI DSS v4.0.1