What Is CSPM (Cloud Security Posture Management)?

Related problems: Worried a storage bucket or database is accidentally open to the internet; Can't see how our AWS, Azure and Google Cloud accounts are configured; Auditors want proof our cloud settings meet a framework; Too many cloud accounts and teams making changes to keep track of by hand

Cloud security posture management (CSPM) is a category of security software that connects to your cloud accounts, continuously checks how resources are configured, and flags settings that break your security policies or common benchmarks, such as storage open to the internet, overly broad permissions or logging turned off. It shows where the risks are, ranks them and guides or automates the fix. Because many cloud incidents start with a misconfiguration rather than a sophisticated attack, CSPM has become a standard part of cloud security for organizations running workloads in AWS, Microsoft Azure, Google Cloud and other platforms.

At a glance

  • For assessment, CSPM reads configuration data from cloud provider APIs with read-only access, usually without installing agents.
  • It compares settings against security best practices, benchmarks and compliance frameworks, then reports and ranks what’s wrong.
  • Many products can open tickets or fix some issues automatically; automatic fixes need separate, narrowly scoped write access, and many teams limit them.
  • It supports compliance evidence but doesn’t make you compliant on its own.
  • It is often sold as part of a broader cloud security platform (CNAPP) alongside workload, identity and data protection.

What problem it solves

In the cloud, anyone with the right permissions can create a database, open a firewall rule or share a storage bucket in seconds. Across dozens of accounts, several teams and more than one cloud provider, nobody can review every change by hand. Under the shared responsibility model, those settings are the customer’s job, not the provider’s, and a single mistake, such as a public bucket holding customer records, can become a data breach.

CSPM gives security and cloud teams one continuous view of how the environment is configured and where it has drifted from policy. It replaces periodic manual reviews and spreadsheets with automated checks, so problems can be caught and fixed sooner, and it gives auditors and customers evidence of how the cloud estate is controlled.

How it works

Connect. The tool is granted read-only access to your cloud accounts, subscriptions or projects through the providers’ APIs, which is enough for discovery and assessment. Some also read Kubernetes clusters and infrastructure-as-code templates.

Inventory. It builds a list of resources: compute, storage, databases, networks, identities and the relationships between them.

Assess. Each resource is checked against rules drawn from provider best practices, industry benchmarks and compliance frameworks, plus any custom policies you add. Typical findings include public storage, unencrypted data, open management ports, unused or over-privileged identities and disabled logging.

Prioritize. Better tools rank findings by context, for example whether a resource is reachable from the internet, holds sensitive data or has risky permissions, so teams don’t drown in low-value alerts.

Remediate. Remediation is a separate step from discovery. With read-only access, the tool provides fix instructions, opens tickets or sends findings to other security tools. Automatic fixes need more: narrowly scoped write permissions, a function deployed in your own account, or integration with your deployment pipeline so the fix is made in code. Organizations that allow automatic fixes usually limit them to a short list, with approvals and audit logs. Checking templates before deployment, part of DevSecOps practice, helps stop the same mistake from being redeployed.

Report. Dashboards and reports show posture over time and map findings to frameworks for audits.

When it matters for buyers

  • When your cloud estate grows past what one person can review. Many accounts, several clouds or multiple engineering teams are the usual trigger.
  • When an audit or customer asks for evidence. Mapped reports help with frameworks such as SOC 2, PCI DSS, HIPAA and ISO/IEC 27001, and with government cloud requirements such as FedRAMP for providers selling to US agencies.
  • When choosing between point tools and a platform. CSPM is often bundled into broader cloud security platforms; decide whether you need posture alone or more.
  • When cyber insurance or a board asks about cloud risk. A posture dashboard gives a measurable answer.
  • When ownership is unclear. CSPM findings need owners; deciding whether security, cloud engineering or application teams fix them is as important as the tool.

Our governance, risk and compliance overview covers how posture findings feed audit evidence and risk reporting.

Questions to ask vendors

  • Which clouds, services and Kubernetes platforms do you cover, and how quickly do you add new services?
  • Do you require agents, or only read-only API access?
  • How do you prioritize findings, and how do you reduce false positives and noise?
  • Which compliance frameworks and benchmarks do you map to, and can we add custom policies?
  • What automatic fixes are available, and how do we control which ones run?
  • What permissions does automatic remediation need beyond read-only access, and how are approvals, audit logs and rollback of automated changes handled?
  • Can you scan infrastructure-as-code templates before deployment?
  • How do you integrate with our ticketing, SIEM and chat tools?
  • How is pricing calculated (per account, resource, workload or cloud spend)?

How it differs from CNAPP

CSPM checks how cloud services and accounts are configured. A cloud-native application protection platform (CNAPP) includes posture management and adds workload protection (CWPP) for virtual machines and containers, and depending on the vendor, entitlement management (CIEM), code scanning and data checks, then correlates the results. CSPM is one component; a CNAPP is the broader platform. Two related tools start from different places: DSPM starts from sensitive data rather than infrastructure, and SSPM checks the settings of SaaS applications rather than cloud infrastructure.

Frequently Asked Questions

Does CSPM make us compliant?
No. CSPM can show whether cloud settings meet the technical checks mapped to a framework such as PCI DSS, HIPAA or ISO/IEC 27001, and produce evidence for auditors. Compliance also depends on policies, processes, people and systems outside the cloud console, which CSPM doesn't see.
Doesn't our cloud provider already handle security?
Only part of it. Under the shared responsibility model, the provider secures the underlying infrastructure, while you are responsible for how you configure your accounts, identities, networks and data. Cloud providers offer native posture tools, and CSPM products build on or add to them, often across several clouds.
Can CSPM fix problems automatically?
Many products can, for example by blocking public access to a storage bucket, but only if you grant more than the read-only access needed for assessment: narrowly scoped write permissions, a function running in your account, or integration with your deployment pipeline. Many organizations limit automatic fixes to a short list of well-understood cases. Changes made outside your deployment pipeline can break applications or be overwritten by the next deployment, so many teams fix findings in code instead.
Is CSPM the same as CNAPP?
No. CSPM is one component. A cloud-native application protection platform (CNAPP) combines posture management with workload protection and, depending on the vendor, identity, code and data checks.
Do we need CSPM if we use only one cloud?
Possibly not as a separate product. Native tools from your cloud provider may be enough for a small, single-cloud estate. A separate product becomes more useful with several clouds, many accounts, tight compliance needs or a need to combine posture findings with other cloud security data.

Related Terms

Cloud-Native Application Protection Platform (CNAPP)

One platform combining cloud posture, workload and app security checks.

Cloud Workload Protection Platform (CWPP)

Security for virtual machines, containers and serverless workloads across clouds.

Cloud Infrastructure Entitlement Management (CIEM)

Finding and trimming excessive permissions for people and machines in cloud infrastructure.

Data Security Posture Management (DSPM)

Software that finds sensitive data, maps access to it and flags risky exposure.

SaaS Security Posture Management (SSPM)

Continuous checks of SaaS app security settings, access and connected apps.

Application Security Posture Management (ASPM)

One view of findings from app security tools, deduplicated and ranked by risk.

Shared Responsibility Model

How security and operational duties are split between a cloud provider and its customer.

Cloud Security

Protecting the data, apps and accounts you run in cloud and SaaS services.

Security Posture

How well an organization is set up to prevent, detect and recover from attacks.

Infrastructure as Code (IaC)

Defining and building infrastructure from version-controlled files instead of by hand.

Continuous Threat Exposure Management (CTEM)

An ongoing program to find, rank, test and fix the exposures that matter most.

DevSecOps

DevOps with security checks and responsibility built into the pipeline.

DevOps

Development and operations working as one, with automated testing and releases.

Federal Risk and Authorization Management Program (FedRAMP)

The US federal program that security-reviews cloud services for agency use.

More Security terms

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.