Skip to main content
Every finding in Security Posture is measured against the standards your organization has to answer to. Athena maps what the scanners find to a set of industry and regulatory frameworks, so a single audit tells you both what’s misconfigured and which controls it affects.

Frameworks covered

Security Posture aligns findings to these frameworks:
  • CIS — the Center for Internet Security benchmarks for hardened configuration.
  • NIST — the U.S. National Institute of Standards and Technology cybersecurity guidance.
  • ISO 27001 — the international standard for information security management.
  • PCI DSS — the payment card industry data security standard.
  • SOC 2 — the trust-services criteria for service organizations.
  • MITRE ATT&CK — the adversary tactics-and-techniques knowledge base.
  • AWS — cloud security and well-architected best practices for AWS.
  • FedRAMP — the U.S. federal cloud security authorization program.
  • CISA — U.S. Cybersecurity and Infrastructure Security Agency guidance.
These same frameworks form the columns of the compliance heatmap on the Security Posture dashboard.

How findings map to frameworks

Each finding is tagged with every framework control it touches. That mapping does two things:
  • The heatmap rolls findings up per framework, so you can see where you’re strong and where you’re exposed against, say, PCI DSS versus CIS.
  • The findings table lets you filter by framework, so you can pull every issue that affects a single standard — useful when you’re preparing for a specific audit.
Use Analyze on a finding to have Athena walk through exactly which controls it maps to and why. See Remediation & risk acceptance.

How scanning works

Findings come from two kinds of scan:

Continuous auditing

A rolling 24-hour audit keeps each enabled target’s posture current without you having to do anything.

On-demand scans

Trigger a Run scan at any time from a target’s detail view when you need a fresh result now.

What gets scanned

Two scanners feed Security Posture, covering both your cloud and your hosts:

Cloud integrations

A cloud posture scanner audits your connected cloud accounts and services. See Integrations.

Host devices

The Myrmex agent runs host-hardening checks on Windows, Linux, and macOS endpoints.
Both feed the same score, heatmap, and findings table, so cloud and host posture live in one view.

Enabling per-target auditing

Auditing is turned on per target, from that device or integration’s own detail view:
1

Open the target

Open a device or integration from the Directory.
2

Go to its Security Posture tab

Each target’s detail view has a Security Posture tab.
3

Enable continuous auditing or run a scan

Turn on the continuous 24-hour audit, or trigger an on-demand Run scan for an immediate result.
Posture scanning is proactive analysis. For active threats, alerts, and investigations, see Detection & Response; for the AI-driven audits you run directly in chat, see AI-driven audits.

Where to go next

Security Posture

The scored dashboard, KPIs, and findings table.

Remediation & risk acceptance

Act on the findings a scan produces.