Cloud security posture management (CSPM) is a category of security software that connects to your cloud accounts, continuously checks how resources are configured, and flags settings that break your security policies or common benchmarks, such as storage open to the internet, overly broad permissions or logging turned off. It shows where the risks are, ranks them and guides or automates the fix. Because many cloud incidents start with a misconfiguration rather than a sophisticated attack, CSPM has become a standard part of cloud security for organizations running workloads in AWS, Microsoft Azure, Google Cloud and other platforms.
At a glance
- For assessment, CSPM reads configuration data from cloud provider APIs with read-only access, usually without installing agents.
- It compares settings against security best practices, benchmarks and compliance frameworks, then reports and ranks what’s wrong.
- Many products can open tickets or fix some issues automatically; automatic fixes need separate, narrowly scoped write access, and many teams limit them.
- It supports compliance evidence but doesn’t make you compliant on its own.
- It is often sold as part of a broader cloud security platform (CNAPP) alongside workload, identity and data protection.
What problem it solves
In the cloud, anyone with the right permissions can create a database, open a firewall rule or share a storage bucket in seconds. Across dozens of accounts, several teams and more than one cloud provider, nobody can review every change by hand. Under the shared responsibility model, those settings are the customer’s job, not the provider’s, and a single mistake, such as a public bucket holding customer records, can become a data breach.
CSPM gives security and cloud teams one continuous view of how the environment is configured and where it has drifted from policy. It replaces periodic manual reviews and spreadsheets with automated checks, so problems can be caught and fixed sooner, and it gives auditors and customers evidence of how the cloud estate is controlled.
How it works
Connect. The tool is granted read-only access to your cloud accounts, subscriptions or projects through the providers’ APIs, which is enough for discovery and assessment. Some also read Kubernetes clusters and infrastructure-as-code templates.
Inventory. It builds a list of resources: compute, storage, databases, networks, identities and the relationships between them.
Assess. Each resource is checked against rules drawn from provider best practices, industry benchmarks and compliance frameworks, plus any custom policies you add. Typical findings include public storage, unencrypted data, open management ports, unused or over-privileged identities and disabled logging.
Prioritize. Better tools rank findings by context, for example whether a resource is reachable from the internet, holds sensitive data or has risky permissions, so teams don’t drown in low-value alerts.
Remediate. Remediation is a separate step from discovery. With read-only access, the tool provides fix instructions, opens tickets or sends findings to other security tools. Automatic fixes need more: narrowly scoped write permissions, a function deployed in your own account, or integration with your deployment pipeline so the fix is made in code. Organizations that allow automatic fixes usually limit them to a short list, with approvals and audit logs. Checking templates before deployment, part of DevSecOps practice, helps stop the same mistake from being redeployed.
Report. Dashboards and reports show posture over time and map findings to frameworks for audits.
When it matters for buyers
- When your cloud estate grows past what one person can review. Many accounts, several clouds or multiple engineering teams are the usual trigger.
- When an audit or customer asks for evidence. Mapped reports help with frameworks such as SOC 2, PCI DSS, HIPAA and ISO/IEC 27001, and with government cloud requirements such as FedRAMP for providers selling to US agencies.
- When choosing between point tools and a platform. CSPM is often bundled into broader cloud security platforms; decide whether you need posture alone or more.
- When cyber insurance or a board asks about cloud risk. A posture dashboard gives a measurable answer.
- When ownership is unclear. CSPM findings need owners; deciding whether security, cloud engineering or application teams fix them is as important as the tool.
Our governance, risk and compliance overview covers how posture findings feed audit evidence and risk reporting.
Questions to ask vendors
- Which clouds, services and Kubernetes platforms do you cover, and how quickly do you add new services?
- Do you require agents, or only read-only API access?
- How do you prioritize findings, and how do you reduce false positives and noise?
- Which compliance frameworks and benchmarks do you map to, and can we add custom policies?
- What automatic fixes are available, and how do we control which ones run?
- What permissions does automatic remediation need beyond read-only access, and how are approvals, audit logs and rollback of automated changes handled?
- Can you scan infrastructure-as-code templates before deployment?
- How do you integrate with our ticketing, SIEM and chat tools?
- How is pricing calculated (per account, resource, workload or cloud spend)?
How it differs from CNAPP
CSPM checks how cloud services and accounts are configured. A cloud-native application protection platform (CNAPP) includes posture management and adds workload protection (CWPP) for virtual machines and containers, and depending on the vendor, entitlement management (CIEM), code scanning and data checks, then correlates the results. CSPM is one component; a CNAPP is the broader platform. Two related tools start from different places: DSPM starts from sensitive data rather than infrastructure, and SSPM checks the settings of SaaS applications rather than cloud infrastructure.
