Skip to content
Notifications
Clear all

Help: Aqua's compliance packs don't map to our internal control framework.

3 Posts
3 Users
0 Reactions
31 Views
(@briank)
Honorable Member
Joined: 3 months ago
Posts: 418
Topic starter   [#16101]

We've been running Aqua Security (specifically the Cloud Security Posture Management and vulnerability management modules) for about nine months. Overall, the technical scanning and runtime protection components are performing to specification. However, we've hit a significant roadblock with the compliance reporting features, which was a key part of our procurement justification.

The issue is that Aqua's pre-built compliance packs (NIST SP 800-53, CIS Benchmarks, PCI DSS, etc.) are presented as monolithic, all-or-nothing frameworks. Our internal control framework is a hybrid, tailored model. It pulls specific controls from NIST and CIS, but also incorporates requirements from our own internal policies and a subset of ISO 27001. We need to demonstrate adherence to *our* framework, not Aqua's interpretation of a standard one.

Attempting to map Aqua's findings to our controls has become a manual, error-prone process. For example:
* Aqua might flag a finding under `CIS Kubernetes Benchmark 1.6.0 - 5.1.6`. In our framework, that maps to `INFRA-K8S-007` and also partially to `GOV-RISK-012`.
* A single Aqua control check (e.g., "Ensure that the seccomp profile is set to docker/default") might satisfy parts of three different internal controls across different domains (Governance, Infrastructure, Container Security).
* Conversely, one of our internal controls might require evidence from *multiple* Aqua checks across different compliance packs, which currently requires running several reports and manually collating the data.

We've looked at the Aqua API and the raw JSON output of scans. While we can technically access the data, the logic to transform it is non-trivial. The compliance pack mappings are not transparently exposed as a data model we can override or extend.

My primary question is: **Has anyone successfully decoupled Aqua's compliance findings from their bundled packs to map them onto a custom, internal control framework?**

I'm looking for concrete approaches, such as:
* Is there a method to define a custom "compliance pack" within Aqua using their UI or API that we've missed?
* Has anyone built an external data pipeline (e.g., using the Aqua API -> transform in Python/Pandas -> load into a dedicated GRC tool) that works in production?
* Are we better off ignoring the compliance module entirely and treating all findings as raw, un-tagged vulnerabilities/misconfigurations, then tagging them ourselves post-hoc?

Any insights into the data schema of the compliance results, or examples of how you've statistically correlated Aqua checks to custom controls, would be invaluable. The lack of this mapping capability is currently forcing us to maintain a parallel, manual control assessment process, which negates much of the efficiency gain we were promised.


p-value < 0.05 or bust


   
Quote
(@franklin)
Estimable Member
Joined: 3 months ago
Posts: 109
 

That sounds really frustrating. We had a similar mapping problem with a different CSPM tool last year. Did Aqua's support team have any suggestions, or are you stuck building a custom parser for their API output?



   
ReplyQuote
(@harryj)
Reputable Member
Joined: 3 months ago
Posts: 381
 

Support didn't have a ready solution, which was a letdown. Their API is definitely the way to go, but parsing it directly is heavy lifting. We used a middle layer - a simple internal app that pulls from the Aqua API, maps findings to our control IDs using a lookup table we maintain, and then pushes the normalized data into our GRC dashboard. It's extra work, but it bridges the gap.


Automate the boring stuff.


   
ReplyQuote