Automation team · internal
Infrastructure
Every cloud resource in the AWS org — what it is, why it's here, who owns it, and its security posture. Findings come from Prowler run against the same CIS, NIST 800-53, PCI-DSS, and AWS Foundational benchmarks, scored and cited the same way as the automation audit.
How it all connects
Three dashboards, one flow. Hover to trace a path; click any box to see how it works inside.
How we score — and how we cut the noise
Findings come from Prowler, an open-source scanner that runs the same control benchmarks as AWS Security Hub (CIS, NIST 800-53, PCI-DSS, AWS Foundational). Raw Prowler is deliberately exhaustive — it flags every best-practice gap, including operational, cost, disaster-recovery, and compliance-niche items that are not security risks for this estate. We triage that in two layers so what you see is signal, not noise.
1 · Tuning policy. A documented allow/mute/downgrade policy removes checks that aren't security risks here (e.g. log-group CMK — logs are already encrypted by default; S3 MFA-delete — needs root, effectively unusable) and corrects Prowler's over-severe ratings. Nothing is deleted: every suppressed finding is shown with its reason under Tuned out.
2 · Adversarial AI review. Two opposing AI reviewers — one hunting false positives, one guarding against under-rating — adjudicate each check, and a per-resource pass asks "does this actually apply to this resource?" Findings judged false-positive or by-design are moved to Tuned out with the reasoning; the rest carry a review note you can read on each card. Confirmed-real findings are marked, and ones needing a live check are flagged.
Score. Every resource starts at 100; we subtract per active finding (Critical 40, High 28, Medium 14, Low 5), floored at 0. 85+ is Good, 70–84 Fair, 50–69 Watch, under 50 Risk.
| Resource | Type | Account | Region | Owner | PHI | Security | Sign-off |
|---|
Every scan is diffed against the previous one. Remediations and new issues are recorded here so a fix is never silently lost — a durable audit trail, kept in the same store as sign-offs.