Skip to content

Compliance ​

Hashiro maps cloud misconfigurations to industry-standard compliance benchmarks, giving you visibility into how your cloud infrastructure aligns with established security frameworks.

CIS Benchmarks ​

The primary compliance framework used by Hashiro is the CIS (Center for Internet Security) Benchmarks: widely recognized best-practice guidelines for securing cloud environments.

Each cloud provider has its own CIS benchmark:

ProviderBenchmark
AWSCIS Amazon Web Services Foundations Benchmark
AzureCIS Microsoft Azure Foundations Benchmark
GCPCIS Google Cloud Platform Foundations Benchmark

Compliance Score ​

Each connected provider account displays a compliance score: the percentage of applicable CIS controls that are passing.

Compliance Score = (Passing Controls / Total Applicable Controls) x 100

The score updates automatically after each scan as misconfigurations are detected or resolved.

Compliance score and benchmarks

Screenshots use fictional demonstration data.

Benchmark Progress ​

Compliance benchmarks are displayed as progress bars showing:

  • Passing: controls where no misconfigurations were found
  • Failing: controls with one or more active misconfigurations
  • Not Applicable: controls that don't apply to your environment (e.g., a control about a service you don't use)

Control Mapping ​

Every misconfiguration in Hashiro is mapped to its corresponding CIS benchmark control. This means you can:

  • Drill down from a benchmark control to see all related misconfigurations
  • Drill up from a misconfiguration to see which compliance controls it affects
  • Track remediation progress at the control level (a control passes only when all related misconfigurations are resolved)

Using Compliance Data ​

Audit Preparation ​

Export compliance reports to demonstrate your organization's security posture to auditors. The compliance view shows which controls are met and which have gaps, along with the specific resources involved.

Prioritization ​

Use compliance alignment to prioritize remediation. Misconfigurations that affect multiple compliance controls or that are required for your regulatory obligations should be addressed first.

Trend Tracking ​

Monitor your compliance score over time to ensure your cloud security posture is improving and that new deployments don't introduce regressions.

TIP

Compliance scores are a useful directional indicator, but they don't replace a thorough security assessment. A high compliance score means you're following established best practices. It doesn't guarantee the absence of all security risks.

Hashiro. Continuous Threat Exposure Management.