Customer Snapshot
| Attribute | Details |
|---|---|
| Industry | SaaS Platform |
| Cloud Environment | AWS (multi-account) |
| Compliance Base | CIS and NIST, with a custom internal framework built on top |
| Existing Evidence | Manually assembled from native tools and open-source scan outputs |
| Team Size | Small security team; DevOps handles remediation |
| Focus Area | CSPM + Compliance |
The Situation: A Custom Framework That No Tool Understood
Plenty of teams adopt CIS or NIST off the shelf. This team went a step further. They started with CIS Benchmarks and NIST controls as their foundation, then built a custom framework on top — mapping industry baselines to their own control language, their own risk categories, and their own internal ownership model.
This is a mark of maturity, not a workaround. It means the security team has thought carefully about which controls matter for their business, how those controls map to real cloud resources, and who is accountable when a control drifts. It is exactly what a good GRC function should produce.
The problem was that no tool in their stack understood that framework. CIS and NIST were partially covered by native tools and open-source scanners, but their custom control structure lived in a spreadsheet. Every audit cycle, someone reconciled scan outputs against custom controls by hand: exporting findings, mapping each one to the right internal control, chasing down evidence, and assembling a report. Weeks of work, repeated every cycle, and stale the moment it was finished.
The Core Tension
The framework was correct. The evidence process was broken. A well-designed custom framework built on CIS and NIST was being validated with manual spreadsheet reconciliation, because the tools generating findings could map to the standard benchmarks but not to the team’s own control structure. The gap was not knowing what to check — it was proving, continuously, that each custom control was satisfied across a live, changing AWS environment.
Where the Gaps Were
Standard Benchmarks, Non-Standard Controls
Native tools and open-source scanners can map findings to CIS Benchmarks and, in some cases, to NIST families. What they cannot do is map to your control IDs. When your framework says “Control DATA-07: no production data store is reachable from the public internet without documented exception,” no off-the-shelf scanner knows what DATA-07 is. It knows about individual CIS recommendations. The translation from CIS recommendation to DATA-07 is manual, and it is done by a human every single time.
Evidence Assembly Was a Recurring Manual Project
Because the mapping was manual, so was the evidence. Each audit required someone to:
- Run scans across every account.
- Export findings from multiple tools.
- Match each finding to the relevant internal control.
- Collect the supporting artifact (a screenshot, a config export, a CLI output).
- Assemble it into a report the auditor would accept.
This is not analysis. It is clerical work, and it consumes the exact senior security time that should be spent on actual risk reduction.
No Continuous Validation Between Audits
A spreadsheet-based framework is a point-in-time snapshot. The day after it is assembled, an engineer modifies a security group, a new account is added, or a storage bucket policy changes — and the framework no longer reflects reality. There is no mechanism that says “Control DATA-07 was satisfied yesterday and is violated today.” Compliance is treated as an event, not a state.
How Cloudanix Addresses This Situation
1,000+ Checks Mapped to CIS and NIST Out of the Box
Cloudanix ships with 1,000+ pre-built checks across AWS services, mapped to CIS, NIST, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. For this team, the CIS and NIST foundation their framework is built on is covered from day one — no rule-writing required to establish the baseline. Findings are continuously evaluated across every connected account, not scanned on a schedule and forgotten.

Bring Your Own Rules: Encoding the Custom Framework
This is the capability that closes the gap. With Bring Your Own Rules (BYOR), the team defines checks that express their own controls, then maps them to their own control IDs. Control DATA-07 stops being a spreadsheet row and becomes an enforced, continuously evaluated check.
BYOR lets the team:
- Author custom checks that reflect internal control intent, not just standard benchmark language.
- Map both standard checks (CIS/NIST) and custom checks to their internal control structure.
- Represent their entire framework — the CIS/NIST base plus the custom layer — inside one platform.
- Evaluate every control continuously, so status is always current.
The framework the team spent real effort designing becomes a living object in the platform, instead of a document that describes an intention no tool enforces.

Evidence That Assembles Itself
Because every control — standard and custom — is continuously evaluated, evidence is a byproduct of the platform operating, not a project someone runs before an audit. For each control, the platform shows current status, the resources evaluated, and the supporting detail. Reports export in formats auditors accept, in PDF or CSV.
The “weeks of reconciliation” problem disappears. When the auditor asks for evidence against internal Control DATA-07, the answer is a filter and an export, not a person and a fortnight.

Accept-Risk With Documented Reason
Real frameworks have exceptions. A control might be intentionally not met for a specific resource, with sign-off. Cloudanix supports accepting risk on a finding with a documented reason and preserved history — so the exception is recorded, attributable, and visible at the next review, rather than silently dropped from a spreadsheet.
Drift Detection Keeps the Framework Honest
Cloudanix builds a baseline automatically on connect and flags drift immediately. When a change moves a resource out of compliance with a mapped control, it surfaces right away — not at the next audit. The custom framework is validated against the live environment continuously, which is the entire point of building one.

Platform Impact
| Dimension | Before | After |
|---|---|---|
| Custom control validation | Manual spreadsheet reconciliation | Continuous, automated per control |
| Evidence assembly | Weeks of manual work per audit | One-click export, always current |
| CIS/NIST coverage | Partial, across multiple tools | 1,000+ checks, mapped out of the box |
| Custom control mapping | Human translation every cycle | Encoded once via BYOR |
| Framework freshness | Stale the day it is finished | Always reflects the live environment |
| Exceptions | Dropped or forgotten | Documented, attributed, and tracked |
Why This Pattern Matters
A custom framework built on CIS and NIST is a sign that a security team has done the hard thinking. The failure mode is not the framework — it is validating a sophisticated framework with an unsophisticated process. When the mapping and the evidence are manual, the quality of the framework is capped by how much clerical work the team can sustain, and senior people spend audit season assembling spreadsheets instead of reducing risk.
Encoding the framework into CSPM with BYOR inverts that. The thinking stays with the humans. The checking, the mapping, and the evidence become continuous and automatic. The framework finally does what it was designed to do — reflect, in real time, whether the environment matches the team’s own definition of secure.
Key Outcomes
- ✅ CIS + NIST Baseline Covered: 1,000+ pre-built checks mapped out of the box.
- ✅ Custom Framework Encoded: BYOR expresses internal controls and maps to your own control IDs.
- ✅ Continuous Validation: Every control evaluated against the live environment, not point-in-time.
- ✅ Self-Assembling Evidence: Audit-ready exports in PDF/CSV, always current.
- ✅ Documented Exceptions: Accept-risk with reason and preserved history.
- ✅ Immediate Drift Detection: Out-of-compliance changes surface as they happen.
Built a Custom Framework on CIS and NIST?
If your team has invested in a custom control framework built on CIS and NIST — and you are validating it with manual spreadsheet reconciliation — Cloudanix encodes that framework into continuous CSPM. Standard benchmarks covered out of the box, custom controls expressed with BYOR, evidence that assembles itself.
Book a Free Assessment to see your custom framework evaluated against your live AWS environment in under 30 minutes.