Open menu

Compliance and Conformity

Last updated: 11 January 2020

Trend Micro Cloud One™ – Conformity provides a number of tools to help organizations quickly assess their infrastructure’s compliance posture against various compliance standards and frameworks:

Compliance tools:

  1. Standard and Framework checks report - view how your organization’s infrastructure is tracking against rules filter by various Standards and Frameworks
  2. Compliance and Conformity Reports - view and download a report assessing how your cloud infrastructure security and governance posture is tracking against controls from various Standards and Frameworks.
  3. Compliance Excel Report - Downloadable Excel report of your infrastructure’s compliance posture.
  4. Compliance Score – health metric of your cloud infrastructure measured against Conformity’s entire 750+ rule set.

Supported Standards and Frameworks

Cloud Conformity currently offers reports for the following standards and frameworks. Each standard or framework is made up of controls that specify security and governance requirements. Conformity rules are mapped to these controls and the resulting checks can be filtered to display only the rules relevant to a particular standard or framework.

Standard or Framework Standard and Framework checks report Compliance and Conformity Reports Compliance Excel Report
AWS Well Architected Framework
 
(NIST) 800-53 (Rev.4)
 
The Center of Internet Security (CIS) AWS Foundations Benchmark v1.2.0
Payment Card Industry Data Security Standard (PCI DSS)
   
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
   
General Data Protection Regulation (GDPR)
   
Australian Prudential Regulation Authority (APRA)
   
Monetary Authority of Singapore Technology Risk Management Guidelines (MAS TRM)
 
NIST Cyber Security Framework v1.1
   
System and Organization Controls (SOC 2)
   
ISO 27001
   
AusGov ISM 2020
   
ASAE 3150 Security of CDR Data
 
HITRUST CSF v9.3
   

Standard and Framework checks report

  1. Open All checks report
  2. Select View by Rule or by Resource
  3. Expand Filter checks
  4. Check a standard or framework in Standards & Frameworks. For Example: Monetary Authority of Singapore TRM

    We currently support the following Standards & Framework filters:
    • AWS Well Architected Framework
    • NIST 800-53 (Rev. 4)
    • CIS Amazon Web Services Foundations Benchmark v1.2.0
    • CIS Microsoft Azure Foundations Benchmark v1.1.0
    • PCI DSS
    • HIPAA
    • ASAE 3150 Security of CDR Data
    • GDPR
    • APRA
    • Monetary Authority of Singapore TRM
    • System and Organization Controls 2 (SOC2)
    • NIST Cyberscecurity Framework v1.1
    • ISO 27001
    • AusGov ISM 2020
    • HITRUST CSF v9.3

  5. Scroll down to the checks list, which will display the standard or framework selected. Click on a rule to see the check result (success or failure) against the rule for each resource. See Rules for more info.
  6. [ Optional ] Download the result as a PDF or CSV report.
    • Generate and download new Standard & Framework Checks results
      1. Click on Generate report
    • Download previously generated reports from the history
      1. Expand Other reports from the Configured reports list
      2. Select either CSV or PDF format for the report
        Note: Standard and Framework checks reports can also be downloaded from All Generated Reports list.

To know more about standards in a particular Standard and Framework report, in most cases you will need to register with the standard from their website to be able to access a detailed PDF about the standards.

Compliance Excel Report

A Compliance Excel Report is mapped in the same way as a Compliance & Conformity Reports however this report is available in XLS format. Currently only supported for CIS AWS Foundations 1.2.0.

Example CIS AWS Foundations report