You’re offline. This is a read only version of the page.
Online Help Center
Search
Support
For Home
For Business
English (US)
Bahasa Indonesia (Indonesian)
Dansk (Danish)
Deutsch (German)
English (Australia)
English (US)
Español (Spanish)
Français (French)
Français Canadien
(Canadian French)
Italiano (Italian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português - Brasil
(Portuguese - Brazil)
Português - Portugal
(Portuguese - Portugal)
Svenska (Swedish)
ภาษาไทย (Thai)
Tiếng Việt (Vietnamese)
Türkçe (Turkish)
Čeština (Czech)
Ελληνικά (Greek)
Български (Bulgarian)
Русский (Russian)
עברית (Hebrew)
اللغة العربية (Arabic)
日本語 (Japanese)
简体中文
(Simplified Chinese)
繁體中文
(Traditional Chinese)
繁體中文 HK
(Traditional Chinese)
한국어 (Korean)
Cancel
This website uses cookies for website functionality and traffic analytics. Our Cookie Notice provides more information and explains how to amend your cookie settings.
Learn More
Yes, I agree
Table of Contents
The page you're looking for can't be found or is under maintenance
Try again later or go to the home page
Go to home page
Cloud One™ – Conformity Help
Conformity Help
Help Topics
Conformity Customer Support
Manage Organisation
Organisation
Organization Details
Administration
Administration Settings
Update Organisation Settings
Manage Users
User
User Settings
User Mobile Number
Two Factor Authentication
Add User
Roles And Permissions
Roles
Administrator
Power User
Read Only
Custom Users
Custom Role
Create a New Custom Role
Map Cloud One Role to Conformity Custom Role
Assign Custom Role to a Cloud One User
Setup Single Sign-On
Set Up SSO For Your Organisation
Conformity SAML 2.0 SSO Certificate Rotation Guide
Introduction
Purpose
Audience
Guide
Troubleshooting
Microsoft Entra ID Saml-SSO Integration
ADFS Saml SSO Integration
Okta Saml SSO Integration Set Up
Onelogin Saml SSO Integration
Manage Cloud Accounts
Cloud Accounts
Add Cloud Accounts
Add Cloud Account
Add An Aws Account
Add A GCP Account
Add an Azure Account
Cloud Account Access
Account Settings
Cloud Account Settings
Cloud Account General Settings
Rule Settings
Rule Settings
New Rules Behaviour
Manage Cloud Account Tags
Cloud Account Tags
Manage Account Groups
Grouped Accounts
Group Settings
Subscriptions
Manage Subscriptions
AWS Marketplace
Self-Serve Subscription (SaaS Contracts)
Sign in
Sign up
Private Offer
Activate your Conformity subscription
Troubleshooting
Problem signing up
Problem configuring the software contract
Renewals
SasS Contracts
Private Offers
Main Dashboard Help
Main Dashboard
Accounts navigation
All accounts
Groups
Individual accounts
Add account or group using UI
Summary Widget
Threat Monitoring Section
Compliance Status Widget
Compliance Evolution
Status per AWS Region
Most Critical Failures
Overview
Report Summary
Compliance Evolution Summary
Conformity Rules
Introduction to Conformity Rules
Contents
What rules does Trend Micro Cloud One™ – Conformity support?
What is the frequency of running the rules?
What rules are run?
New Accounts
Rules configuration
Rule settings
Anatomy of a rule
Check summary
Not Scored
Possible 'Not Scored' Scenarios
Deprecated Rules
Rules supported by Real Time Monitoring
FAQs
Cloud Sentry FAQs
Checks
Model Check
What are Checks?
Viewing Checks
Check Actions
Failure and Success Definition
Not Scored Checks
Failed Check Resolution
Steps to resolve failures
Auto-remediation
Auto Remediation
Content
How does auto-remediation work
Set up auto-remediation
Enable or disable rules after deploying auto-remediation
Testing auto-remediation deployment
Resolution using Manual notifications
Verify the auto-remediation resolution
Contribution to Auto-remediation project
Rules Suppress Check
Send Rule to
Configurations
Rules Configuration
Configure Rules For Friendly Accounts
Rule Categories
Search
Filter and Search
Contents
Filter tags
Filter tags Exact Match
Filter tags Partial Match
Resource Id syntax
Regular expression syntax
Reserved characters
Standard operators
Wildcard syntax
Only show checks
How it works
CQL Filter Method
Contents
Logical operators
Resource Wildcards
Resource regular expressions
Fields list
Using CQL to filter your checks
Query examples
Conformity Custom Rules
Custom Rules Vs Conformity Rules
Custom Rule Types
Comparison
An Overview of Conformity Custom Rules
Introduction
Key Feature Summary
Using Custom Rules
Custom Rule Configuration
Anatomy of a custom rule configuration
Definitions
General parameters
Resource parameters
Rule parameters
Operators
Example Configurations
Check Results
API Endpoints
Frequently Asked Questions
Getting Started with Conformity Custom Rules
Prerequisites
Initial Set-Up
Workflow 1: creating, running, updating and deleting a custom rule
Saving and running your first custom rule (with Conformity Bot)
Dry-run an existing saved rule
Update, test, disable, and delete an existing saved custom rule
Workflow 2: Working with the ‘Dry Run’ feature to build out a rule
Dry-running a draft rule configuration against an account
Returning Resource Data using the Run Endpoint
Testing a new custom rule template using dummy data
Building a new custom rule for another service
Workflow 3: Exploring more advance custom rules logic
Multiple and/or Nested conditions
Workflow 4: Building rules for specific accounts or applying exceptions
Conformity Custom Rules Example Templates
Conformity Custom Rules Quick Reference Guide
API Reference
Checking Basic Set Up
Query Resource Data
Workflow 1: creating, running, updating and deleting a custom rule
Saving and running your first custom rule (with Conformity Bot)
Dry-run an existing saved rule
Update, test, disable, and delete an existing saved custom rule
Workflow 2: Working with the ‘Dry Run’ feature to build out a rule
Dry-running a draft rule configuration against an account
Returning Resource Data using the Run Endpoint
Testing a new custom rule template using dummy data
Building a new custom rule for another service
Workflow 3: Exploring more advance custom rules logic
Multiple and/or Nested conditions
Workflow 4: Building rules for specific accounts or applying exceptions
Reports
Rules Status reports
All Checks Report
Configured Reports
Cloud Posture Report
Generate And Download Report
Compliance
Compliance And Conformity
Supported Standards and Frameworks
Standard and Framework checks report
Compliance Excel Report
Example CIS AWS Foundations report
Compliance Reports
Compliance Score
Custom Compliance Standards
About Custom Compliance Standards
Concepts and Terminology
How to Create/Read/Update/Delete (CRUD) a Custom Compliance Standard using the API?
Custom Compliance Standards API Features
Disabling or deleting an in-use Custom Compliance Standard
Features you can access in the Conformity UI
Example - Creating Custom Compliance Standard for CIS Amazon Web Services Foundations Benchmark v2.0.0
Maintaining a Custom Compliance Standard
Debugging Validation Errors in the Custom Compliance Standard
Example Template
Monitoring Real Time Threats
Real-Time Threat Monitoring
Setup Real-Time Threat Monitoring
Access Real-Time Threat Monitoring
Uninstall Real-Time Threat Monitoring
Real Time Threat Monitoring Settings
Activity Dashboard
Monitoring Dashboard
Communication and Notification
Supported notifications
Re-run historical check notifications
Communication Settings
Settings for Notifications
Toggle Automatic Notifications
Communication Triggers
Communication Recipients
Copy Communication Settings
Toggle Manual Notifications
Communication Channels
Communication Integrations
Email Communication
Sms Communication
Slack Communication
Pagerduty Communication
Jira Communication
Jira Integration
Oauth Client Jira Setup
Zendesk Communication
ServiceNow Communication
Amazon SNS Communication
Microsoft Teams Communication
Webhook Communication
Conformity Bot Help
Conformity Bot
Configuring Conformity Bot
Conformity Bot Settings
Disable Conformity Bot
Conformity Bot Enabled Regions
Conformity Bot Frequency
Conformity Bot - AWS
AWS Integration
Supported regions
Unsupported regions
AWS Well-Architected Tool
Aws Custom Policy
Azure Integration
Add Access Policy for Key Vault Attributes
Firewall Enabled Keyvaults
Conformity Bot - GCP
Add Conformity IP address to GCP Access Level Policy
Adding an access level to an existing perimeter
Conformity IP Addresses
Profiles
Manage Profile
Template Scanner
Template Scanner
Template Scanner Github App
How to install the Template Scanner Github App?
How to configure what gets scanned?
Available configuration
Special characters for matching a path portion:
Note on the use of dots (.)
Examples:
Supported infrastructure as code
CloudFormation YAML and JSON
Supported resource types:
Terraform
Supported resource types:
How to trigger a scan?
Template Scanner Github App
How to install the Template Scanner Github App?
How to configure what gets scanned?
Available configuration
Special characters for matching a path portion:
Note on the use of dots (.)
Examples:
Supported infrastructure as code
CloudFormation YAML and JSON
Supported resource types:
Terraform
Supported resource types:
How to trigger a scan?
Template Scanner Examples
AWS CloudFormation Example
AWS Cloud Development Kit (CDK) Example
Terraform (AWS) Example
Serverless Framework (AWS) Example
Public API
Setup Public API
API Keys
Performance
Performance Troubleshooting
Vision One Cloud Posture
Trend Vision One Cloud Posture Feature Parity
Upgrading to Trend Vision One Cloud Posture
User Scenarios
Deciding which path best suits your organization
Trend Vision One Cloud Posture
New or Existing Trend Micro customer interested in Cloud Posture
Existing Cloud One Conformity or Standalone Conformity User Interested in Trend Vision One Cloud Posture
Upgraded Features and Functionalities
Activating Trend Vision One for Cloud One Customers
Existing Cloud One Conformity or Standalone Conformity User Interested in the Cloud Data Forwarder
FAQs
Trend Vision One Cloud Data Forwarder
Overview
Haven't Signed up for Conformity?
Existing Conformity Customers
Trend Cloud One - Conformity
Conformity Standalone (Legacy)
Common User Scenarios
Common User Scenarios
Getting Started With Conformity
Contents
Review Organization Details
Add Cloud Accounts
Get familiar with the Dashboard
Enable Real-time Threat monitoring
Create a Profile
Configure Rules
Set up Communication Channels and configure notifications
Configure Scheduled Reports
Assess your current Cloud Security
Invite users
Running A Proof Of Concept On Conformity
Entry Criteria
Success Criteria
Visibility Use Cases
Remediation
Customization and Usability
DevOps stories
Our assistance during your POC
Real Time Alerts For Suspicious Activity And Events On My Cloud Infrastructure
Automate Remediation Of Non Compliant Events To Meet Best Practice Policies
Generate Custom Reports For Your Cloud Infrastructure For Management Meetings
Ensure A New Aws Service Added To Your Existing Infrastructure Is Cloud Best Practice Compliant
Prevent Non Compliant Cloudformation Templates From Entering Your Infrastructure
Assessing The Security Posture Of An Existing Cloud Project For The First Time
Relevant users
Cloud Conformity Solution
Part 1 - Creating a report to assess your current security posture
Part 2 - Creating a remediation plan based on your report
Aws Outposts For Conformity
Relevant users
Security Management
Security Rules
View check failures for security rules
Filter report by security rules
API reference
Conformity Bot - AWS
Related information
AWS Integration
Aws Custom Policy
Table of Contents
Cloud One™ – Conformity Help
Conformity Help
Help Topics
Conformity Customer Support
Manage Organisation
Organisation
Organization Details
Administration
Administration Settings
Update Organisation Settings
Manage Users
User
User Settings
User Mobile Number
Two Factor Authentication
Add User
Roles And Permissions
Roles
Administrator
Power User
Read Only
Custom Users
Custom Role
Create a New Custom Role
Map Cloud One Role to Conformity Custom Role
Assign Custom Role to a Cloud One User
Setup Single Sign-On
Set Up SSO For Your Organisation
Conformity SAML 2.0 SSO Certificate Rotation Guide
Introduction
Purpose
Audience
Guide
Troubleshooting
Microsoft Entra ID Saml-SSO Integration
ADFS Saml SSO Integration
Okta Saml SSO Integration Set Up
Onelogin Saml SSO Integration
Manage Cloud Accounts
Cloud Accounts
Add Cloud Accounts
Add Cloud Account
Add An Aws Account
Add A GCP Account
Add an Azure Account
Cloud Account Access
Account Settings
Cloud Account Settings
Cloud Account General Settings
Rule Settings
Rule Settings
New Rules Behaviour
Manage Cloud Account Tags
Cloud Account Tags
Manage Account Groups
Grouped Accounts
Group Settings
Subscriptions
Manage Subscriptions
AWS Marketplace
Self-Serve Subscription (SaaS Contracts)
Sign in
Sign up
Private Offer
Activate your Conformity subscription
Troubleshooting
Problem signing up
Problem configuring the software contract
Renewals
SasS Contracts
Private Offers
Main Dashboard Help
Main Dashboard
Accounts navigation
All accounts
Groups
Individual accounts
Add account or group using UI
Summary Widget
Threat Monitoring Section
Compliance Status Widget
Compliance Evolution
Status per AWS Region
Most Critical Failures
Overview
Report Summary
Compliance Evolution Summary
Conformity Rules
Introduction to Conformity Rules
Contents
What rules does Trend Micro Cloud One™ – Conformity support?
What is the frequency of running the rules?
What rules are run?
New Accounts
Rules configuration
Rule settings
Anatomy of a rule
Check summary
Not Scored
Possible 'Not Scored' Scenarios
Deprecated Rules
Rules supported by Real Time Monitoring
FAQs
Cloud Sentry FAQs
Checks
Model Check
What are Checks?
Viewing Checks
Check Actions
Failure and Success Definition
Not Scored Checks
Failed Check Resolution
Steps to resolve failures
Auto-remediation
Auto Remediation
Content
How does auto-remediation work
Set up auto-remediation
Enable or disable rules after deploying auto-remediation
Testing auto-remediation deployment
Resolution using Manual notifications
Verify the auto-remediation resolution
Contribution to Auto-remediation project
Rules Suppress Check
Send Rule to
Configurations
Rules Configuration
Configure Rules For Friendly Accounts
Rule Categories
Search
Filter and Search
Contents
Filter tags
Filter tags Exact Match
Filter tags Partial Match
Resource Id syntax
Regular expression syntax
Reserved characters
Standard operators
Wildcard syntax
Only show checks
How it works
CQL Filter Method
Contents
Logical operators
Resource Wildcards
Resource regular expressions
Fields list
Using CQL to filter your checks
Query examples
Conformity Custom Rules
Custom Rules Vs Conformity Rules
Custom Rule Types
Comparison
An Overview of Conformity Custom Rules
Introduction
Key Feature Summary
Using Custom Rules
Custom Rule Configuration
Anatomy of a custom rule configuration
Definitions
General parameters
Resource parameters
Rule parameters
Operators
Example Configurations
Check Results
API Endpoints
Frequently Asked Questions
Getting Started with Conformity Custom Rules
Prerequisites
Initial Set-Up
Workflow 1: creating, running, updating and deleting a custom rule
Saving and running your first custom rule (with Conformity Bot)
Dry-run an existing saved rule
Update, test, disable, and delete an existing saved custom rule
Workflow 2: Working with the ‘Dry Run’ feature to build out a rule
Dry-running a draft rule configuration against an account
Returning Resource Data using the Run Endpoint
Testing a new custom rule template using dummy data
Building a new custom rule for another service
Workflow 3: Exploring more advance custom rules logic
Multiple and/or Nested conditions
Workflow 4: Building rules for specific accounts or applying exceptions
Conformity Custom Rules Example Templates
Conformity Custom Rules Quick Reference Guide
API Reference
Checking Basic Set Up
Query Resource Data
Workflow 1: creating, running, updating and deleting a custom rule
Saving and running your first custom rule (with Conformity Bot)
Dry-run an existing saved rule
Update, test, disable, and delete an existing saved custom rule
Workflow 2: Working with the ‘Dry Run’ feature to build out a rule
Dry-running a draft rule configuration against an account
Returning Resource Data using the Run Endpoint
Testing a new custom rule template using dummy data
Building a new custom rule for another service
Workflow 3: Exploring more advance custom rules logic
Multiple and/or Nested conditions
Workflow 4: Building rules for specific accounts or applying exceptions
Reports
Rules Status reports
All Checks Report
Configured Reports
Cloud Posture Report
Generate And Download Report
Compliance
Compliance And Conformity
Supported Standards and Frameworks
Standard and Framework checks report
Compliance Excel Report
Example CIS AWS Foundations report
Compliance Reports
Compliance Score
Custom Compliance Standards
About Custom Compliance Standards
Concepts and Terminology
How to Create/Read/Update/Delete (CRUD) a Custom Compliance Standard using the API?
Custom Compliance Standards API Features
Disabling or deleting an in-use Custom Compliance Standard
Features you can access in the Conformity UI
Example - Creating Custom Compliance Standard for CIS Amazon Web Services Foundations Benchmark v2.0.0
Maintaining a Custom Compliance Standard
Debugging Validation Errors in the Custom Compliance Standard
Example Template
Monitoring Real Time Threats
Real-Time Threat Monitoring
Setup Real-Time Threat Monitoring
Access Real-Time Threat Monitoring
Uninstall Real-Time Threat Monitoring
Real Time Threat Monitoring Settings
Activity Dashboard
Monitoring Dashboard
Communication and Notification
Supported notifications
Re-run historical check notifications
Communication Settings
Settings for Notifications
Toggle Automatic Notifications
Communication Triggers
Communication Recipients
Copy Communication Settings
Toggle Manual Notifications
Communication Channels
Communication Integrations
Email Communication
Sms Communication
Slack Communication
Pagerduty Communication
Jira Communication
Jira Integration
Oauth Client Jira Setup
Zendesk Communication
ServiceNow Communication
Amazon SNS Communication
Microsoft Teams Communication
Webhook Communication
Conformity Bot Help
Conformity Bot
Configuring Conformity Bot
Conformity Bot Settings
Disable Conformity Bot
Conformity Bot Enabled Regions
Conformity Bot Frequency
Conformity Bot - AWS
AWS Integration
Supported regions
Unsupported regions
AWS Well-Architected Tool
Aws Custom Policy
Azure Integration
Add Access Policy for Key Vault Attributes
Firewall Enabled Keyvaults
Conformity Bot - GCP
Add Conformity IP address to GCP Access Level Policy
Adding an access level to an existing perimeter
Conformity IP Addresses
Profiles
Manage Profile
Template Scanner
Template Scanner
Template Scanner Github App
How to install the Template Scanner Github App?
How to configure what gets scanned?
Available configuration
Special characters for matching a path portion:
Note on the use of dots (.)
Examples:
Supported infrastructure as code
CloudFormation YAML and JSON
Supported resource types:
Terraform
Supported resource types:
How to trigger a scan?
Template Scanner Github App
How to install the Template Scanner Github App?
How to configure what gets scanned?
Available configuration
Special characters for matching a path portion:
Note on the use of dots (.)
Examples:
Supported infrastructure as code
CloudFormation YAML and JSON
Supported resource types:
Terraform
Supported resource types:
How to trigger a scan?
Template Scanner Examples
AWS CloudFormation Example
AWS Cloud Development Kit (CDK) Example
Terraform (AWS) Example
Serverless Framework (AWS) Example
Public API
Setup Public API
API Keys
Performance
Performance Troubleshooting
Vision One Cloud Posture
Trend Vision One Cloud Posture Feature Parity
Upgrading to Trend Vision One Cloud Posture
User Scenarios
Deciding which path best suits your organization
Trend Vision One Cloud Posture
New or Existing Trend Micro customer interested in Cloud Posture
Existing Cloud One Conformity or Standalone Conformity User Interested in Trend Vision One Cloud Posture
Upgraded Features and Functionalities
Activating Trend Vision One for Cloud One Customers
Existing Cloud One Conformity or Standalone Conformity User Interested in the Cloud Data Forwarder
FAQs
Trend Vision One Cloud Data Forwarder
Overview
Haven't Signed up for Conformity?
Existing Conformity Customers
Trend Cloud One - Conformity
Conformity Standalone (Legacy)
Common User Scenarios
Common User Scenarios
Getting Started With Conformity
Contents
Review Organization Details
Add Cloud Accounts
Get familiar with the Dashboard
Enable Real-time Threat monitoring
Create a Profile
Configure Rules
Set up Communication Channels and configure notifications
Configure Scheduled Reports
Assess your current Cloud Security
Invite users
Running A Proof Of Concept On Conformity
Entry Criteria
Success Criteria
Visibility Use Cases
Remediation
Customization and Usability
DevOps stories
Our assistance during your POC
Real Time Alerts For Suspicious Activity And Events On My Cloud Infrastructure
Automate Remediation Of Non Compliant Events To Meet Best Practice Policies
Generate Custom Reports For Your Cloud Infrastructure For Management Meetings
Ensure A New Aws Service Added To Your Existing Infrastructure Is Cloud Best Practice Compliant
Prevent Non Compliant Cloudformation Templates From Entering Your Infrastructure
Assessing The Security Posture Of An Existing Cloud Project For The First Time
Relevant users
Cloud Conformity Solution
Part 1 - Creating a report to assess your current security posture
Part 2 - Creating a remediation plan based on your report
Aws Outposts For Conformity
Relevant users
Security Management
Security Rules
View check failures for security rules
Filter report by security rules
API reference