> For the complete documentation index, see [llms.txt](https://docs.sec1.io/user-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sec1.io/user-docs/11-cspm.md).

# CSPM (Cloud Security Posture Management)

## Introduction

Sec1 CSPM gives you continuous, **agentless, read-only** visibility into the security posture of your cloud estate. You connect a cloud account with a read-only credential, the Sec1 platform inventories your resources, and it continuously checks them for misconfigurations, compliance gaps, exposure, identity risk, and exploitable attack paths — then prioritises what to fix first and helps you remediate it.

Sec1 CSPM scans **Google Cloud (GCP)**, **Microsoft Azure**, **AWS**, and **Kubernetes** (GKE, AKS, and EKS). Nothing is ever written back to your cloud — every credential Sec1 asks for is read-only.

{% hint style="info" %}
**One-line model:** add a cloud account → provide a read-only credential → test the connection → run a scan → review assets, findings, compliance, and attack paths in the Sec1 console.
{% endhint %}

## Key Features

These map to the core CSPM capability areas Sec1 covers:

* **Asset inventory** — auto-discover and catalogue every resource across your connected cloud accounts and clusters.
* **Misconfiguration detection** — out-of-the-box rules for common misconfigurations (public storage, open ingress, weak IAM, unencrypted data, and more), with severity and contextual remediation guidance, suppression with audit trail, and drift tracking over time.
* **Compliance management** — \~12 frameworks out of the box (CIS, PCI DSS, ISO 27001, SOC 2, NIST CSF, NIST 800-53, CSA CCM, FedRAMP, CIS Controls), control-ID mapping, scoring, and exportable reports.
* **Attack path analysis** — visualise chained risks from external exposure to critical assets, see blast radius, and get remediation that breaks the path at the optimal point.
* **Prioritisation & threat intelligence** — risk-based scoring that factors in exposure, asset criticality, and exploit context, so you see the top risks to fix now rather than a flat severity list.
* **Kubernetes misconfiguration detection** — cluster RBAC over-permission, privileged pods, exposed dashboards, network policy gaps, and CIS Kubernetes Benchmark checks on GKE and AKS.
* **AI-assisted remediation & Ask-AI** — guided fixes and a natural-language assistant for investigating findings.
* **Point-in-time trends, reporting & ticketing** — historical posture snapshots, PDF + CSV reports, Jira ticketing and assignment, and team-based access.

## Getting Started

Work through these pages in order:

1. [**Prerequisites**](/user-docs/11-cspm/1-prerequisites.md) — the read-only access model, network reachability, identity, supported providers, and the SaaS vs hybrid/on-prem split.
2. [**Required Permissions**](/user-docs/11-cspm/2-permissions.md) — copy-pasteable read-only role lists for GCP, Azure, AWS, and Kubernetes (GKE / EKS / AKS), with a summary table.
3. [**Onboarding & Your First Scan**](/user-docs/11-cspm/3-onboarding.md) — add a cloud account in the Sec1 console, test the connection, run a scan, and view results.
4. [**Frameworks, Coverage & FAQ**](/user-docs/11-cspm/4-frameworks-and-coverage.md) — supported compliance frameworks, what gets scanned, reporting/exports, and frequently asked questions.

{% hint style="success" %}
**Start small.** You can onboard a single project or subscription with the minimum read-only roles, run a scan, and expand coverage (Kubernetes, more accounts) later.
{% endhint %}

{% hint style="info" %}
**Onboarding at scale.** Beyond a single account, you can onboard at **organization scope** — grant the read-only roles once at a GCP organization/folder or an Azure management group, and Sec1 discovers all child projects/subscriptions for you to multi-select and onboard in one flow. See [Onboarding](/user-docs/11-cspm/3-onboarding.md#onboard-at-organization-scope-multiple-projects--subscriptions).
{% endhint %}
