GlossaryAttack surface and pentesting

CSPM

Short answer

CSPM (Cloud Security Posture Management) is a category of tools that continuously check cloud environments such as AWS, Azure and Google Cloud for misconfigurations and compliance gaps, such as public storage, excessive permissions or disabled logging, and help fix them.

Why misconfiguration is the main cloud risk

Under the shared responsibility model, the cloud provider secures the infrastructure, while the customer is responsible for how services are configured. A storage bucket left public, a database open to the internet, an access key with full administrator rights or logging turned off are common causes of cloud data breaches, and they can appear at any moment as teams deploy changes.

What CSPM does

It connects to cloud accounts through their APIs, builds an inventory of resources, checks configurations against security benchmarks such as the CIS Benchmarks and frameworks like ISO 27001 or SOC 2, and prioritises findings by risk. Many tools can also fix common issues automatically or alert the owner.

Related categories

CSPM is often part of a broader cloud native application protection platform (CNAPP), which also covers workloads, containers and code. SSPM applies the same idea to SaaS applications such as Microsoft 365 or Google Workspace, and is linked to SaaS management.

Where it shows up in compliance

ISO 27001 includes information security for the use of cloud services (Annex A 5.23) and configuration management (8.9). Continuous configuration checks provide evidence for audits and are a key input to a company's overall security posture.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub