The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Cloudvisory Release Notes 5.1.0

Prev Next

Cloudvisory Security Platform

Software Changes

Highlights

  • Added support for creation of business units at the Azure subscription level.

  • Implemented open text search on Access and Identity Inspector page.

  • Implemented peak workloads and assets for the overall deployment and individual provider types which can be viewed on the dashboard by a user with administrator privileges.

  • Added Provider Type as a new column and as a filter in the Network Object page.

  • Reporting improvements:

    • Improved the compliance report format.

    • Created and updated template report NIST 800-53 r5 for AWS, Azure, and GCP.

    • Created and updated template report PCI DSS for AWS, Azure, and GCP.

    • Added support for AWS CMMC level 3 compliance template report.

  • Migrated compliance AWS and GCP CIS checks to the latest version.

  • Migrated compliance Azure CIS checks to version 1.3.1.

  • Added support for selecting multiple values from the search filter dropdown when creating a new compliance check.

  • Show port information for Kubernetes Service in Visualization properties.

  • Added support for Port Safeguard in Openstack.

  • Added support for Azure network security group (NSG) flow logs v2.

  • Added ability to send a separate email with only the password for newly created user.

  • Added event-based discovery propagators and handlers for new AWS discoveries.

  • Discover new assets for AWS, Azure, and GCP (See New Asset Types Discovered Section below.)

  • Removed Account ID of the S3 bucket(s) from the Add provider screen.

  • Improved performance for filtering by Attached interface/subnet in Azure security group.

Fixed Issues

  • Performance timeout issue in Compliance reports.

  • Appcontrol stops updating workloads, when license limit reached.

  • Compliance groups of sub-accounts are not automatically created during the creation of an Organization account.

  • Asset Inventory: Null Pointer Exception when viewing the VM that doesn't have a name.

  • Calendar issue on Dashboard and Compliance Checks Inspector.

  • Visualization - No network flow for the specific account(s) that a Business Unit admin manages.

  • Terraform checks are added automatically into the cloud compliance group when it is auto created upon adding cloud provider.

  • Network Group creation fails in a high load environment.

  • Business Unit: A BU user could manage his or her own BU.

  • User passwords show as plain text in the logs.

  • Unable to edit GCP provider account.

  • Unable to edit Azure provider account.

  • Edit Azure provider account: 'FlowStorageResourceGroup:' is not a required field when 'Share Access Signature' is checked.

  • Unable to see Public and Private IPs in the Asset Inventory page.

  • Asset Inventory: filter name was called 'VM with Public IP' instead of 'Asset with Public IP'.

  • Unable to discover GCP SQL database instances.

  • Checks Available page: CheckType is always 'Custom Policy' after cloning check from other check types.

  • Risk Score update message did not consider AssetType (just AssetId) - this caused issues with Azure assets that can have the same AssetId for multiple asset types.

Known Issues

  • Compliance Inspector - view check details: Detail are not showing for deleted check.

  • Openstack VMs do not set flag for IP public address.

  • Business Unit admins are able to see recommendations for provider account(s) that they do not manage.

  • Compliance check details: paging issue for results when using open text search.

  • Network security group: paging issue on open text search.

  • Admins who do not have configuration permissions can see the pulldown menu. (UI issue only - they see an empty page if they select a menu option, and therefore cannot update permissions)

  • Recommendations are not supported for microsegmentation in Openstack network policies.

  • AWS/EKS or Azure/AKS K8S are also exported as provider account(s) when exporting an AWS and Azure provider account.

New Asset Types Discovered

AWS

  • AWS Access Analyzer

  • AWS Account Password Policy

  • AWS Athena Workgroup

  • AWS CloudWatch Metric Alarm

  • AWS CloudWatch Log Group

  • AWS Detective Graph

  • AWS EC2 Account Attribute

  • AWS Glue Crawler

  • AWS Guard Duty Detector

  • AWS Guard Duty Finding

  • AWS Macie Job

  • AWS OpenID Connector Provider

  • AWS Organization Tag Policy

  • AWS BackupPolicy

  • AWS iService Opt Out Policy

  • AWS Round Table

  • AWS Server Certificate

  • AWS SAML Provider

  • AWS Stackset

  • AWS Stackset Instance

  • AWS WAF WebACL

  • Added Public Access Block Configuration field to AWS S3 Bucke

Azure

  • Azure Activity Log Alerts

  • Azure Diagnostic Settings

  • Azure Disk encryption set

  • Azure Spring Cloud

  • Azure Spring App

  • Azure Virtual Network

  • Added Server Vulnerability Assessment property for SQL Servers

  • Added Azure defender pricing bundles in Azure Subscriptions

  • Added Data Export Settings and Alert Sync Settings in Azure Subscription

  • Added Data Table Service properties to Azure Storage Account

GCP

  • GCP Bigquery Table

  • Azure Diagnostic Settings

New Compliance Checks

AWS

  • aws-001-013:1.4.0 Ensure there is only one active access key available for any single IAM user

  • aws-001-019:1.4.0 Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed

  • aws-001-020:1.4.0 Ensure that IAM Access analyzer is enabled for all regions

  • aws-001-021:1.4.0 Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments

  • aws-002-101:1.4.0 Ensure all S3 buckets employ encryption-at-rest

  • aws-002-102:1.4.0 Ensure S3 Bucket Policy is set to deny HTTP requests

  • aws-002-103:1.4.0 Ensure MFA Delete is enable on S3 buckets

  • aws-002-104:1.4.0 Ensure all data in Amazon S3 has been discovered, classified and secured when required

  • aws-002-105:1.4.0 Ensure that Amazon S3 Buckets are configured with 'Block public access (bucket settings)

  • aws-002-201:1.4.0 Ensure EBS volume encryption is enabled

  • aws-003-010:1.4.0 Ensure that Object-level logging for write events is enabled for S3 bucket

  • aws-003-011:1.4.0 Ensure that Object-level logging for read events is enabled for S3 bucket

  • aws-004-015:1.4.0 Ensure a log metric filter and alarm exists for AWS Organizations changes

  • aws-005-001:1.4.0 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports

  • aws-005-004:1.4.0 Ensure routing tables for VPC peering are 'least access'

  • aws-200-170:1.0.0 Ensure AWS Guard Duty Detector is enabled

  • aws-200-169:1.0.0 Ensure AWS WAF is used to protect the web application

  • aws-200-171:1.0.0 Ensure that user does not have excessive privileges

Azure

  • azr-200-039:1.1.0 - Maximum number of rules in a network security group

  • azr-004-308:1.3.1 Ensure 'Allow access to Azure services' for PostgreSQL Database Server is disabled

  • azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server

  • azr-004-201:1.3.1 Ensure that Advanced Threat Protection (ATP) on a SQL server is set to 'Enabled'

  • azr-004-202:1.3.1 Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account

  • azr-004-203:1.3.1 Ensure that VA setting Periodic Recurring Scans is enabled on a SQL server

  • azr-004-204:1.3.1 Ensure that VA setting Send scan reports to is configured for a SQL server

  • azr-002-001:1.3.1 Ensure that Azure Defender is set to On for Servers

  • azr-002-002:1.3.1 Ensure that Azure Defender is set to On for App Service

  • azr-002-003:1.3.1 Ensure that Azure Defender is set to On for Azure SQL database servers

  • azr-002-004:1.3.1 Ensure that Azure Defender is set to On for SQL Servers on machines

  • azr-002-005:1.3.1 Ensure that Azure Defender is set to On for Storage

Copyright © 2021 Cloudvisory Documentation, FireEye Inc.

3

  • azr-002-006:1.3.1 Ensure that Azure Defender is set to On for Kubernetes

  • azr-002-007:1.3.1 Ensure that Azure Defender is set to On for Container Registries

  • azr-002-008:1.3.1 Ensure that Azure Defender is set to On for Key Vault

  • azr-002-009:1.3.1 Ensure that Windows Defender ATP (WDATP) integration with Security Center is selected

  • azr-002-010:1.3.1 Ensure that Microsoft Cloud App Security (MCAS) integration with Security Center is selected

  • azr-002-012:1.3.1 Ensure any of the ASC Default policy setting is not set to Disabled

  • azr-002-015:1.3.1 Ensure that 'All users with the following roles' is set to 'Owner'

  • azr-003-008:1.3.1 Ensure soft delete is enabled for Azure Storage

  • azr-003-009:1.3.1 Ensure storage for critical data are encrypted with Customer Managed Key

  • azr-003-010:1.3.1 Ensure Storage logging is enabled for Blob service for read, write, and delete requests

  • azr-003-011:1.3.1 Ensure Storage logging is enabled for Table service for read, write, and delete requests

  • azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server

  • azr-005-003:1.3.1 Ensure that Diagnostic Logs are enabled for all services which support it

  • azr-005-101:1.3.1 Ensure that a 'Diagnostics Setting' exists

  • azr-005-102:1.3.1 Ensure Diagnostic Setting captures appropriate categories

  • azr-005-202:1.3.1 Ensure that Activity Log Alert exists for Delete Policy Assignment

  • azr-006-006:1.3.1 Ensure that UDP Services are restricted from the Internet

  • azr-007-001:1.3.1 Ensure Virtual Machines are utilizing Managed Disks

  • azr-007-007:1.3.1 Ensure that VHD's are encrypted

  • azr-009-010:1.3.1 Ensure FTP deployments are disabled

  • azr-001-023:1.3.1 Ensure Custom Role is assigned for Administering Resource Locks

GCP

  • gcp-002-012:1.2.0 Ensure that Cloud DNS logging is enabled for all GCP VPC networks

  • gcp-004-011:1.2.0 Ensure that GCP Compute instances have Confidential Computing enabled

  • gcp-006-303:1.2.0 Ensure 'user connections' database flag for GCP Cloud SQL SQL Server instance is set as appropriate

  • gcp-006-304:1.2.0 Ensure 'user options' database flag for GCP Cloud SQL SQL Server instance is not configured

  • gcp-006-305:1.2.0 Ensure 'remote access' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-006-306:1.2.0 Ensure '3625 (trace flag)' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-007-003:1.2.0 Ensure that a Default Customer-managed encryption key (CMEK) is specified for all GCP BigQuery Data Sets

  • gcp-006-207:1.2.0 Ensure 'log_statement' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-208:1.2.0 Ensure 'log_hostname' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-209:1.2.0 Ensure 'log_parser_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-210:1.2.0 Ensure 'log_planner_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-211:1.2.0 Ensure 'log_executor_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-212:1.2.0 Ensure 'log_statement_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-213:1.2.0 Ensure that the 'log_min_messages' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-214:1.2.0 Ensure 'log_min_error_statement' database flag for GCP Cloud SQL PostgreSQL instance is set to 'Error' or stricter

  • gcp-006-102:1.2.0 Ensure 'skip_show_database' database flag for GCP Cloud SQL Mysql instance is set to 'on'

  • gcp-006-202:1.2.0 Ensure 'log_error_verbosity' database flag for GCP Cloud SQL PostgreSQL instance is set to 'DEFAULT' or stricter

  • gcp-006-205:1.2.0 Ensure 'log_duration' database flag for GCP Cloud SQL PostgreSQL instance is set to 'on'

  • gcp-006-301:1.2.0 Ensure 'external scripts enabled' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-007-002:1.2.0 Ensure that all GCP BigQuery Tables are encrypted with Customer-managed encryption key (CMEK)