Environment:Production (VPS-EU-1)
Compliance Findings & Violations
Active evaluation findings, violations, and real-time remediation playbooks across your cloud infrastructure.
CRITICALFAILAWS•SOC 2 CC6.2 • ISO 27001 A.5.18 • HIPAA § 164.312(a)(1)
Orphan Zombie Account: Terminated Employee Retains Active AWS IAM Keys
arn:aws:iam::123456789012:user/former.employeeFirst Detected: 2 hours ago
Employee former.employee@company.com suspended in Google Workspace 30 days ago, but AWS IAM AccessKey AKIAIOSFODNN7EXAMPLE is still active.
Remediation Playbook
aws iam delete-access-key --user-name former.employee --access-key-id AKIAIOSFODNN7EXAMPLE
HIGHFAILAWS•ISO 27001 A.8.24 • HIPAA § 164.312(a)(2)(iv) • GDPR Art. 32
S3 Bucket Server-Side Encryption Disabled
arn:aws:s3:::legacy-unencrypted-mediaFirst Detected: 1 day ago
Bucket legacy-unencrypted-media does not have default AES256 or AWS-KMS encryption enabled.
Remediation Playbook
Enable SSE-S3 default encryption in S3 Properties console or via AWS CLI.
HIGHFAILAWS•ISO 27001 A.8.24 • HIPAA § 164.312(a)(2)(iv)
RDS PostgreSQL Storage Encryption Not Enabled
arn:aws:rds:us-east-1:123456789012:db:unencrypted-analytics-dbFirst Detected: 3 days ago
Database instance unencrypted-analytics-db has StorageEncrypted: false.
Remediation Playbook
Create encrypted DB snapshot and restore to a new encrypted RDS instance.
HIGHPASSAWS•SOC 2 CC6.1 • ISO 27001 A.9.4.2 • HIPAA § 164.312(d)
Multi-Factor Authentication Enforced on All Active IAM Users
arn:aws:iam::123456789012:user/alex.devFirst Detected: 1 week ago
User alex.dev has active virtual MFA device registered.
HIGHPASSGCP•ISO 27001 A.8.24 • GDPR Art. 32
GCS Bucket Default CMEK Encryption Enabled
gcs-company-prod-secure-dataFirst Detected: 2 weeks ago
Bucket protected by Google Cloud KMS customer-managed key.