Configuration checks
Review pass and fail results for your cloud and identity configuration, and request a fix or an exception.
- Who can do this: Admin
- In the app: Exposure › Configuration
- 10 min
Exposure › Configuration shows pass and fail results from configuration checks run against a connected cloud or SaaS tenant (an integration), with the framework controls each check relates to. Connect the integration under Settings › Integrations (see Integrations) and open this page from your organisation's main project as an Admin on it.
Review your checks
- Open Exposure › Configuration and select the integration.
- On the Checks tab, search for a check or resource, then narrow by status and severity. The status filter opens on Failing.
- Expand a check to see the resources failing it, then open one for its description, how to remediate and the evidence collected.
Request a fix or an exception
Both requests are added to Actions › Proposals.
- Open a failing resource from the Checks tab.
- To ask for a fix, choose Create proposal.
- To record a known exception, choose Create exception, optionally enter why the failing check is acceptable, and choose Submit exception request.
Refresh results and propose fixes in bulk
On the integration's detail page, Sync now collects the latest data from your tenant, and Derive actions proposes remediation actions for its failing checks.
Print or share results
Choose New report then Configuration in Governance › Reports; see Reports.
Did this answer your question?
Identity exposures
Review leaked credentials and account addresses found in breaches and on the dark web, resolve them once the account is secured, and reveal a leaked password.
Risk
Record a risk in the Risk register, score it by likelihood and impact, choose how to treat it, link the controls that reduce it, and track it to closure.