Description |
Lacework periodically updates policies and reports to reflect the latest benchmarks, such as CIS, SOC2, PCI-DSS, ISO, NIST, etc. |
Scope |
The updated CIS-based policies offer increased accuracy, comprehensive checks and ensure you are staying current with industry best practices. You’ll gain better coverage and documentation on how to remediate compliance issues, as well as enhanced alerting that reflects severity in consensus with AWS, Azure, Google Cloud, and the Lacework security engineering team.
These latest benchmarks – for example CIS 1.4 for AWS, CIS 1.5 for Azure, and CIS 1.3 for Google Cloud – are enabled automatically as they are implemented.
As part of this ongoing effort, Lacework periodically deprecates policies associated with legacy benchmarks. |
Solution |
Migrate existing exceptions to the latest benchmarks
When deprecation occurs, you can utilize the Lacework CLI to migrate your existing exceptions/suppression logic to the new benchmarks.
Using version 1.8.0 or greater of the CLI, run the following:
For support on migrating your legacy suppressions to the new compliance policies, please contact your account team.
NOTE: By running the above commands, users are accepting responsibility for the suppression of any compliance violations missed as a result of the added exceptions. If you are using suppressions in AWS CIS 1.1 policies, we encourage you to immediately migrate your legacy suppressions to equivalent policy exceptions to avoid alert duplicates.
Policy Changes
Policy changes are automatic; you don’t need to perform any actions to receive the latest policies and benchmarks.
To ensure that your CSPM assessments are up to complete and accurate on an ongoing basis:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.