CloudSCAPEFeatures
Automated daily scanning of GCC 2.0 cloud resources for compliance with Singapore Government IM8 Reform. Findings are assessed against the controls defined in each subsystem's System Security Plan (SSP), with results reflecting the Risk Materiality Level (RML) (Low-Risk, Medium-Risk, or High-Risk) and set of controls applicable to each system.
CloudSCAPE findings surface in the Security Centre on Console, giving agencies a consolidated view of security posture and IM8 Reform compliance across their cloud accounts.
Analyses AWS Identity and Access Management (IAM) configurations to identify dangerous permission combinations across users, groups, roles, and policies that could lead to privilege escalation or lateral movement within the environment.
Allows users to categorise non-compliant findings based on their current state to help manage remediation efforts and track progress. Users can add notes to capture follow-up actions and justifications, and bulk update related findings to manage them efficiently at scale.
Provides APIs for programmatic access to platform data, including IM8 compliance and Attack Mapper findings. Agencies can retrieve this data and integrate it into their own reporting and analysis workflows without manual exports.
Roadmap
Turns supported security findings into review-ready fixes for Terraform code. CloudSCAPE uses an AI agent to generate fixes for the misconfigured resources and raises a Merge Request in the agency's SHIP-HATS GitLab project, which developers review, adjust if needed, and merge. This shortens the path from finding to fix while keeping agencies in control over what enters their codebase.
