AWS and Cloudanix team co-authored this blog: Real-Time Threat and Anomaly Detection for Workloads on AWS

Cloudanix – Your Partner in Cloud Security Excellence

Building a Custom Compliance Framework on Top of CIS and NIST With CSPM

  • Tuesday, Sep 15, 2026

Customer Snapshot

AttributeDetails
IndustrySaaS Platform
Cloud EnvironmentAWS (multi-account)
Compliance BaseCIS and NIST, with a custom internal framework built on top
Existing EvidenceManually assembled from native tools and open-source scan outputs
Team SizeSmall security team; DevOps handles remediation
Focus AreaCSPM + Compliance

The Situation: A Custom Framework That No Tool Understood

Plenty of teams adopt CIS or NIST off the shelf. This team went a step further. They started with CIS Benchmarks and NIST controls as their foundation, then built a custom framework on top — mapping industry baselines to their own control language, their own risk categories, and their own internal ownership model.

This is a mark of maturity, not a workaround. It means the security team has thought carefully about which controls matter for their business, how those controls map to real cloud resources, and who is accountable when a control drifts. It is exactly what a good GRC function should produce.

The problem was that no tool in their stack understood that framework. CIS and NIST were partially covered by native tools and open-source scanners, but their custom control structure lived in a spreadsheet. Every audit cycle, someone reconciled scan outputs against custom controls by hand: exporting findings, mapping each one to the right internal control, chasing down evidence, and assembling a report. Weeks of work, repeated every cycle, and stale the moment it was finished.

The Core Tension

The framework was correct. The evidence process was broken. A well-designed custom framework built on CIS and NIST was being validated with manual spreadsheet reconciliation, because the tools generating findings could map to the standard benchmarks but not to the team’s own control structure. The gap was not knowing what to check — it was proving, continuously, that each custom control was satisfied across a live, changing AWS environment.

Where the Gaps Were

Standard Benchmarks, Non-Standard Controls

Native tools and open-source scanners can map findings to CIS Benchmarks and, in some cases, to NIST families. What they cannot do is map to your control IDs. When your framework says “Control DATA-07: no production data store is reachable from the public internet without documented exception,” no off-the-shelf scanner knows what DATA-07 is. It knows about individual CIS recommendations. The translation from CIS recommendation to DATA-07 is manual, and it is done by a human every single time.

Evidence Assembly Was a Recurring Manual Project

Because the mapping was manual, so was the evidence. Each audit required someone to:

  • Run scans across every account.
  • Export findings from multiple tools.
  • Match each finding to the relevant internal control.
  • Collect the supporting artifact (a screenshot, a config export, a CLI output).
  • Assemble it into a report the auditor would accept.

This is not analysis. It is clerical work, and it consumes the exact senior security time that should be spent on actual risk reduction.

No Continuous Validation Between Audits

A spreadsheet-based framework is a point-in-time snapshot. The day after it is assembled, an engineer modifies a security group, a new account is added, or a storage bucket policy changes — and the framework no longer reflects reality. There is no mechanism that says “Control DATA-07 was satisfied yesterday and is violated today.” Compliance is treated as an event, not a state.

How Cloudanix Addresses This Situation

1,000+ Checks Mapped to CIS and NIST Out of the Box

Cloudanix ships with 1,000+ pre-built checks across AWS services, mapped to CIS, NIST, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. For this team, the CIS and NIST foundation their framework is built on is covered from day one — no rule-writing required to establish the baseline. Findings are continuously evaluated across every connected account, not scanned on a schedule and forgotten.

Cloudanix CSPM — Findings mapped to compliance frameworks across accounts

Bring Your Own Rules: Encoding the Custom Framework

This is the capability that closes the gap. With Bring Your Own Rules (BYOR), the team defines checks that express their own controls, then maps them to their own control IDs. Control DATA-07 stops being a spreadsheet row and becomes an enforced, continuously evaluated check.

BYOR lets the team:

  • Author custom checks that reflect internal control intent, not just standard benchmark language.
  • Map both standard checks (CIS/NIST) and custom checks to their internal control structure.
  • Represent their entire framework — the CIS/NIST base plus the custom layer — inside one platform.
  • Evaluate every control continuously, so status is always current.

The framework the team spent real effort designing becomes a living object in the platform, instead of a document that describes an intention no tool enforces.

Cloudanix Compliance — Control-level mapping with supporting evidence

Evidence That Assembles Itself

Because every control — standard and custom — is continuously evaluated, evidence is a byproduct of the platform operating, not a project someone runs before an audit. For each control, the platform shows current status, the resources evaluated, and the supporting detail. Reports export in formats auditors accept, in PDF or CSV.

The “weeks of reconciliation” problem disappears. When the auditor asks for evidence against internal Control DATA-07, the answer is a filter and an export, not a person and a fortnight.

Cloudanix Compliance — Exportable evidence with control history

Accept-Risk With Documented Reason

Real frameworks have exceptions. A control might be intentionally not met for a specific resource, with sign-off. Cloudanix supports accepting risk on a finding with a documented reason and preserved history — so the exception is recorded, attributable, and visible at the next review, rather than silently dropped from a spreadsheet.

Drift Detection Keeps the Framework Honest

Cloudanix builds a baseline automatically on connect and flags drift immediately. When a change moves a resource out of compliance with a mapped control, it surfaces right away — not at the next audit. The custom framework is validated against the live environment continuously, which is the entire point of building one.

Cloudanix — Automatic baseline and drift detection

Platform Impact

DimensionBeforeAfter
Custom control validationManual spreadsheet reconciliationContinuous, automated per control
Evidence assemblyWeeks of manual work per auditOne-click export, always current
CIS/NIST coveragePartial, across multiple tools1,000+ checks, mapped out of the box
Custom control mappingHuman translation every cycleEncoded once via BYOR
Framework freshnessStale the day it is finishedAlways reflects the live environment
ExceptionsDropped or forgottenDocumented, attributed, and tracked

Why This Pattern Matters

A custom framework built on CIS and NIST is a sign that a security team has done the hard thinking. The failure mode is not the framework — it is validating a sophisticated framework with an unsophisticated process. When the mapping and the evidence are manual, the quality of the framework is capped by how much clerical work the team can sustain, and senior people spend audit season assembling spreadsheets instead of reducing risk.

Encoding the framework into CSPM with BYOR inverts that. The thinking stays with the humans. The checking, the mapping, and the evidence become continuous and automatic. The framework finally does what it was designed to do — reflect, in real time, whether the environment matches the team’s own definition of secure.

Key Outcomes

  • CIS + NIST Baseline Covered: 1,000+ pre-built checks mapped out of the box.
  • Custom Framework Encoded: BYOR expresses internal controls and maps to your own control IDs.
  • Continuous Validation: Every control evaluated against the live environment, not point-in-time.
  • Self-Assembling Evidence: Audit-ready exports in PDF/CSV, always current.
  • Documented Exceptions: Accept-risk with reason and preserved history.
  • Immediate Drift Detection: Out-of-compliance changes surface as they happen.

Built a Custom Framework on CIS and NIST?

If your team has invested in a custom control framework built on CIS and NIST — and you are validating it with manual spreadsheet reconciliation — Cloudanix encodes that framework into continuous CSPM. Standard benchmarks covered out of the box, custom controls expressed with BYOR, evidence that assembles itself.

Book a Free Assessment to see your custom framework evaluated against your live AWS environment in under 30 minutes.

Related Resources

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo