Our cloud environment requires to be compliant based on the CIS profile. This means that after a security and compliance scan we need to be notified if any non-compliant controls have been found. This is required also by the auditor to prove that we have setup the environment for automatic notification in such a case.
At the moment the Security and Compliance framework allows only to select a maximum of 15 controls from the profile for which notification will be sent in case of non-compliance.
This does not really makes sense, as we need to select only a part of the controls from the profile and ignore the rest. It should be a basic functionality to allow notification for all the controls from the profile, as from both compliance and auditing perspective this is a must to have a notification in case anything from the profile is non-compliant.
| Idea priority | High |
| Needed By | Month |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.