Multiple AWS accounts, of any size and "scope", may be configured as AWS Provider Accounts in CSP. For each configured AWS Provider Account – CSP continuously discovers and processes new and updated assets, metadata, security controls & security events for all in-scope Cloud Services, Regions, and VPCs. By processing updates according to policies configured in CSP – and through the same cloud-native API integrations – events trigger governance actions such as compliance remediation and policy enforcement. In this way, CSP provides Visibility, Compliance & Governance for AWS assets, metadata, security controls & security events such as:
- AWS CloudTrail Events
- AWS CloudWatch Logs
- AWS EC2 Instances
- AWS Elastic IPs
- AWS IAM Users
- AWS IAM Roles
- AWS Lambda Functions
- AWS Regions
- AWS S3 Buckets
- AWS Tags
- AWS VPCs
- AWS VPC Flow Logs