> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zero-x.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# 6.1 Remediation

# Cloud Security – Complete Detailed (End‑User & Admin Guide)

***

## 1. Introduction to Cloud Security Modules

This manual provides a deep, end‑to‑end understanding of Cloud Security operations. It covers onboarding cloud data sources, scanning, viewing results, understanding CSPM components, and performing remediation.<br />

It is intended for: - **End Users** (Analysts, Security Engineers)<br />

***

## 2. What is CSPM (Cloud Security Findings Management)?

CSPM is a security solution that continuously monitors your cloud environment to identify misconfigurations, compliance violations, security risks, and potential attack paths.<br />

**CSPM Helps With:**<br />
**>** Detecting insecure cloud configurations<br />
**>** Identifying risky public exposure<br />
**>** Monitoring excessive permissions<br />
**>** Evaluating compliance frameworks (CIS, NIST, PCIDSS, etc.)<br />
**>** Providing remediation steps (manual or AI-driven)<br />

CSPM ensures that your cloud environment remains secure, compliant, and aligned with best practices.<br />

***

## 3. Breakdown of CSPM Components

Below are detailed explanations of each security category visible after scans:

***

### 3.1 Misconfiguration

Misconfigurations occur when cloud resources are not configured according to security best practices.<br />

**Examples:**<br />
**>** S3 buckets allowing public read access<br />
**>** IAM roles with overly permissive policies<br />
**>** Security groups with open ports (0.0.0.0/0)<br />
**>** Unencrypted storage (EBS, RDS, Blob)<br />

***

### 3.2 Permissions (CIEM – Cloud Infrastructure Entitlement Management)

This module focuses on IAM and identity security.<br />

**What it detects:**<br />
**>** Excessive permissions<br />
**>** Unused permissions<br />
**>** Privilege escalation risks<br />
**>** Roles/users with admin-like access<br />

**Why it matters:**<br />
Attackers exploit excessive IAM permissions to compromise accounts.<br />

***

### 3.3 Public Exposure

Shows cloud assets that are unintentionally exposed to the internet.<br />

**Examples:**<br />
**>** Public S3 buckets<br />
**>** Public VMs/EC2 instances<br />
**>** Public Blob Storage<br />
**>** Open database endpoints<br />

**Why it matters:**<br />
Public exposure leads to data leakage, ransomware, or unauthorized access.<br />

***

### 3.4 Exploitable

Indicates cloud configurations that can be actively exploited by attackers.<br />

**Examples:**<br />
**>** Weak IAM roles + public resource exposure<br />
**>** Misconfigured network rules with known vulnerabilities<br />

**Why it matters:**<br />
Exploitable items represent **high-risk** attack paths.<br />

***

### 3.5 Vulnerability

Lists vulnerabilities (CVEs) found in workloads, VMs, containers, or cloud services.<br />

**Examples:**<br />
**>** Outdated OS packages<br />
**>** Vulnerable container images<br />
**>** Known exploitable CVEs affecting cloud workloads<br />

**Why it matters:**<br />
Vulnerabilities can be directly used to execute malware or privilege escalation.<br />

***

## 4. End‑to-End Cloud Security Workflow

Below is the complete step-by-step process for both end-users and admins.

***

### Step 1 – Add Cloud Data Source (End User)

**Navigation:**<br />
Connectors → Data Source → Add Data Source<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/AWSAccount.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=66ac369753902510af0d026a829d0c75" alt="Alt text" width="1897" height="825" data-path="images/datasources/AWSAccount.png" />

**Steps:**<br />
**1.** Click **Add Data Source**.<br />
**2.** Select Cloud Provider (AWS / Azure / GCP).<br />
**3.** Step 1 - Enter required details (Account ID, Access Key ID, Secret Access Key, etc.).<br />

<img src="https://mintcdn.com/infimatrix/hdj8CnMy2GHELsJt/images/datasources/aws.png?fit=max&auto=format&n=hdj8CnMy2GHELsJt&q=85&s=e9eb9b0e7d8cd1059e1c9b6a3e637bc3" alt="Alt text" width="1918" height="877" data-path="images/datasources/aws.png" />

**4.** Click **Verify and Next**.<br />
**5.** Step 2 - System Auto Sync and reflect Cloud Trail, ECR, EKS Cluster, and user can choose from dropdowns which Cloud Trail, ECR, EKS Cluster system should sync.<br />
**6.** Once validated, click **Connect**.<br />

**Outcome:**<br />
**>** System triggers **Auto Inventory Scan**.<br />
**>** System triggers **Auto Cost Scan**.<br />

***

### Step 2 – Automatic Inventory & Cost Sync

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/scans.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=cc814bce383037da1c4b795f433ca332" alt="Alt text" width="1896" height="825" data-path="images/datasources/scans.png" />

**Inventory Module:**<br />
**>** Lists all cloud resources across all regions.<br />
**>** Resource filtering and search become available.<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/inventory.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=029f86b1a9bf5e60e2d7f0af7792f0a2" alt="Alt text" width="1896" height="819" data-path="images/datasources/inventory.png" />

**Cost Module:**<br />
**>** Displays total cost, service breakdown, and region-wise cost.<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/costModule.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=3024aa1f2db3e6be0e19233b95d4afc6" alt="Alt text" width="1896" height="820" data-path="images/datasources/costModule.png" />

***

### Step 3 – Enable Compliances for CSPM (End User)

**Navigation:**<br />
**Compliance → Available**<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/compliance01.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=7fe9f8f97737b3f818385de37637b5da" alt="Alt text" width="1893" height="823" data-path="images/datasources/compliance01.png" />

**Steps:**<br />
**1.** Open the **Compliance Module**.<br />
**2.** In the **Available** tab, enable required frameworks.<br />
**3.** Enabled items move to the Enabled tab.<br />

**Outcome:**<br />
**>** These compliances are used during CSPM scans.<br />

***

### Step 4 – Perform a New Security Scan (End User)

### Navigation:

**Scan → New Scan**<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/scansnow.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=e818ef2123769a59ea6e497482c82198" alt="Alt text" width="1881" height="817" data-path="images/datasources/scansnow.png" />

**Steps:**<br />
**1.** Click **New Scan**.<br />
**2.** Select:<br />
   - Cloud Platform<br />
   - Scan Type (Compliance, CSPM, CIEM, etc.)<br />
   - Account<br />
**3.** Start Scan.<br />

**Outcome:**<br />
**>** Findings get generated and stored.<br />

***

### Step 5 – View Findings Across Modules

**Navigation Paths:**<br />
**>** **Scan → Scan Results**<br />
**>** **Security Findings → CSPM Dashboard**<br />
**>** **Security Findings → Misconfiguration**<br />
**>** **Security Findings → Permissions**<br />
**>** **Security Findings → Public Exposure**<br />
**>** **Security Findings → Exploitable**<br />
**>** **Security Findings → Vulnerability**<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/security.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=9c3c046289ab2785b951a4f43da12fdd" alt="Alt text" width="1893" height="820" data-path="images/datasources/security.png" />

**Details Available:**<br />
**>** Severity: Critical / High / Medium / Low<br />
**>** Impact & Risk Summary<br />
**>** Affected Resources<br />
**>** Compliance Mapping<br />
**>** Remediation Steps<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/securityDashboard.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=a6b15bd2396f78d5e2fcdd2f636c27b3" alt="Alt text" width="1894" height="820" data-path="images/datasources/securityDashboard.png" />

***

### Step 6 – Remediation Options

The platform supports two remediation paths:

***

#### A. AI-Based Remediation (End User)

### Navigation:

**CSPM → Misconfiguration → Select Finding → Remediation Tab**<br />

<img src="https://mintcdn.com/infimatrix/aV18YptROE4VwzJQ/images/datasources/remediatin.png?fit=max&auto=format&n=aV18YptROE4VwzJQ&q=85&s=7c5facc59aae31cb1868f91981587792" alt="Alt text" width="1915" height="820" data-path="images/datasources/remediatin.png" />

**Steps:**<br />
**1.** Open a misconfiguration finding.<br />
**2.** Switch to **Remediation** tab.<br />
**3.** Click **AI Generation Script**.<br />
**4.** System generates automated remediation.<br />
**5.** Click **Execute** to apply the fix.<br />

**Outcome:**<br />
**>** Issue gets resolved automatically.<br />

***

#### B. Manual Remediation (End User Execution)

**End User Steps:**<br />
**>** When viewing a finding:<br />
   - Go to Remediation tab.<br />
   - If a script exists for that check, the Execute button appears.<br />
   - Click Execute to remediate.<br />
