April 7, 2026, Conformity: A summary of Trend Cloud One Conformity updates for the week ending on 27 March 2026.
New compliance frameworks
AWS Security Reference Architecture
We've released compliance support for AWS Security Reference Architecture, with coverage
of both core architecture and AI security frameworks. You can now filter checks and
generate reports based on these latest AWS provided recommendations.
Updated compliance standards: CIS Foundations Benchmarks
We've updated our compliance standards to meet the Center for Internet Security (CIS)
Foundations Benchmarks for Amazon Web Services. You can now filter checks and download
compliance reports to ensure your cloud environment complies with the latest CIS Foundations
Benchmarks.
- CIS Amazon Web Services Foundations Benchmark v7.0.0
Deprecation notice
CIS AWS Foundations Benchmark v5.0.0 is no longer supported. We recommend updating
your report configurations to use the latest versions of CIS AWS Foundations Benchmark
before July 7, 2026.
New Rules
OCI
-
OCI-Functions-003: Check for Private Subnet Deployment for Function Applications: This rule ensures that Oracle Cloud Infrastructure (OCI) Functions applications are deployed in private subnets to minimize exposure to the public internet.
-
OCI-Functions-007: Restrict Function Access by Network Source: This rule ensures that IAM policies restrict function access using network source conditions to allow operations only from approved IP address ranges.
-
OCI-ObjectStorage-007: Enable Auto-Tiering for Object Storage Buckets: This rule ensures that Auto-Tiering is enabled for Oracle Cloud Infrastructure (OCI) Object Storage buckets.
Updated Rules
Azure
-
ActiveDirectory-001: Enable Multi-Factor Authentication for Privileged Users: This rule ensures that Multi-Factor Authentication is enabled for all user credentials that have write access to the cloud resources within your Microsoft Azure account.
-
ActiveDirectory-002: Enable Multi-Factor Authentication for Non-Privileged Users: This rule ensures that the Multi-Factor Authentication feature is enabled for all non-privileged users.
-
ActiveDirectory-024: Enable Security Defaults: This rule ensures that Security Defaults is enabled for Microsoft Entra ID.
