For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/cloud/is-aikido-a-cspm.md.
Cloud Security ↗

Is Aikido a CSPM? What its cloud module covers

Aikido includes cloud posture checks. Assess its configuration coverage, permissions and reporting against the cloud risks you need to manage.

AI-generated illustration: Aikido concept linking cloud configuration risks and code.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

Yes. Aikido includes cloud security posture management, or CSPM, within its wider security platform. The module checks cloud configuration for settings that can expose systems and data.

That answers the product-category question. Whether it meets your requirements depends on the accounts, services and controls you need to cover.

What to expect from cloud posture checks

Aikido’s CSPM documentation describes checks for issues such as public storage, open network access and excessive permissions. It supports connections to AWS, Azure and Google Cloud and describes its posture connection as agentless, with permissions to read configuration.

Review the actual connection policy before granting it. Read access to configuration still reveals useful information about your environment, including resource names, network layout and security settings.

A useful finding should identify the resource, explain the risk and point the owner towards a correction. It also needs enough context to distinguish a deliberate public service from accidental exposure.

Use the finding where the change belongs

A cloud console can show an insecure setting even when the source of that setting is a Terraform file. Correcting only the live resource may last until the next deployment restores the old configuration.

Connect posture findings to the team and repository that control the resource. Infrastructure-as-code scanning can help catch configuration issues before deployment; CSPM checks the environment after deployment. The two views answer different questions.

Record accepted exceptions with an owner, a reason and a review date. Otherwise the finding will either return repeatedly or disappear into an exclusion nobody remembers.

Establish the coverage limits

Configuration checks do not, by themselves, show what a running process is doing or whether an attacker has used a credential. Runtime detection, detailed entitlement analysis and sensitive-data discovery each need their own coverage assessment.

Ask for a supported-service list and map it to your inventory. Check how frequently results refresh, what happens when a connection fails and which reporting or compliance integrations are included in the proposed plan.

A product’s control mappings can support an audit. They do not establish that the organisation operates every control required for certification.

FM’s Aikido offering can be assessed against that requirement list. Start with the cloud risks you need to manage, then identify which are covered and who will act on the findings.

← Back to all insights
Questions or inquiry? [email protected] Contact us →