Overview
The Cloud security page gives you one place to see the security posture of your connected cloud accounts. The page surfaces the risky misconfigurations, over-permissioned IAM, and exposed resources as follows:
- Cloud misconfigurations (Cloud Security Posture Management - CSPM): Settings across your cloud accounts that leave resources exposed or weakly protected.
- Over-permissioned IAM identities (Cloud Infrastructure Entitlement Management - CIEM): Users, roles, and service identities that hold more access than they use. This lens shows you which identities can cause real damage, rather than only which identities exist.
How it works
After you connect a cloud account, Hearth reads the configuration of that account and evaluates it against a set of detectors. Hearth groups the issues into the lenses above and stores them for each workspace, so that the picture builds up over time. Cloud security assesses AWS, Azure, and GCP.
Elements of the Cloud security page
The following table describes the elements of the page:
| Element | Description |
|---|---|
| Issues | Displays the cloud misconfigurations and the over-permissioned IAM identities, each with the affected account and resource. They are grouped by triage state – Flagged, Open, Snoozed, Accepted, Hidden, False positive – one row per resource with provider, severity, and fix details. |
| Coverage line | States what this release supports. The release covers CSPM and CIEM for your connected accounts. CWPP and DSPM are not yet available. |
| Row quick actions | Snooze 1 week and Hide |
| Row ⋯ menu | Accept risk (90d), False positive, Prioritize, and Custom snooze… |
| Hestia actions | Investigate with Hestia and Ask Hestia how to fix, which send the issue to Hestia |
Issue statuses
Every issue starts in the Open status. You can prioritize an issue to flag it, or choose one of the suppressing actions to move the issue out of the Open list. Hearth surfaces an accept or a snooze again when that action expires, and you can reopen a suppressed issue at any time.
Connecting a cloud account
Hearth reads the configuration of a cloud account only after you connect it. Add your data sources on the Integrations page by following the steps provided in each setup guide.
Triaging an issue
To work an issue, do the following:
- Navigate to the Cloud security page (Posture > Cloud security).
- Review the summary at the top of the page.
- Review the issues.
Note: An identity issue names the user, role, or service account, the permissions that the identity holds, and the reason for the flag. Hearth usually flags an identity because its access is broader than the access that it uses, or because it grants a sensitive capability. - Do one of the following:
- Fix the issue in your cloud provider.
- Click Snooze 1 week or Hide.
- Click the ⋯ menu, and then click [Accept risk (90d) | False positive | Prioritize | Custom snooze…].
- (Optional) To act on a suppressed issue again, reopen it.
Troubleshooting common issues
| Issue | What to do |
|---|---|
| A provider displays no issues | Confirm that the cloud account is connected. Coverage reflects connected accounts that Hearth has assessed. |
| You can view issues but do not see the options to accept, snooze, or hide them | Triage requires the “Run investigations” permission. Ask an administrator for the permission that you need. |