As an application owner or SRE, you must ensure that your resource configurations meet a predefined industry standard or government benchmark such as CIS, PCI DSS, ISO, or others. The following steps show you how to create, edit, or clone a compliance framework and publish it. Then, you can apply a filter of the findings for the compliance framework.
You can create, edit, or clone a compliance framework. You can also associate policies with the compliance framework, and create a control group and a control.
To create a compliance framework:
Create a control group that organizes the policies in the compliance framework.
For example, control groups can include control plane components, control plane configuration, worker nodes, policies, and managed services. Each control group includes a number of controls that you can select.
Click the link to the framework. For example, CIS AWS Foundations Benchmark version 2.0.0.
The policies in the compliance framework appear.
Click Control Group / Control.
To edit a compliance framework:
Click the link to the compliance framework.
For example, locate the most recent version of CIS AWS Foundations Benchmark, such as version 2.0.0.
Add or remove policies, and click Associate.
Your updated version appears in the list of compliance frameworks.
To clone a compliance framework:
Select the check box next to a compliance framework, and click Clone.
For example, locate the most recent version of CIS AWS Foundations Benchmark, such as version 2.0.0.
Update the version, resource URL, or resource display name, and click Clone.
To activate a compliance framework that corresponds to a governance benchmark that you must apply to your accounts, follow these steps.
Locate the compliance framework that you must publish.
For example, locate the most recent version of CIS AWS Foundations Benchmark, such as version 2.0.0.
Select the check box next to the compliance framework, and click Publish.
When you publish the compliance framework, it gets published as an option in the filters, reports, and dashboards.
If you’ve set up projects in VMware Tanzu Platform hub, you can publish and view compliance frameworks for a specific project by selecting it from the context switcher in the top menu for VMware Tanzu Platform hub.
After you publish a compliance framework, you can create a filter for the associated findings and prioritize them for resolution to ensure that your accounts comply with the selected benchmark.
Select the compliance framework that you created, or one of interest, and click Apply.
For example, locate the most recent version of CIS AWS Foundations Benchmark, such as version 2.0.0.
The findings for the compliance framework that you selected appear in priority order based on the attention score.
You can view the compliance dashboard from the Tanzu Platform hub Home tab to get a general overview of adherence to published compliance frameworks for all connected accounts.
In Tanzu Platform hub, click Security Posture > Overview.
Click the drop-down icon next to the “Security Posture Overview” text and select Compliance.
Resolve the filtered findings according to your organization’s security prioritizations to ensure that your accounts comply with your chosen governance benchmark. For more information, see Investigate VMware Tanzu Platform hub Security Posture findings.
Parent topic:Define and apply governance policies in VMware Tanzu Platform hub