What problem does it solve?
CIS benchmark findings are hard to translate into consistent, auditable security guidance for Azure environments, especially when evidence is scattered across identity settings, Defender for Cloud, networking, storage, databases, and Key Vault.
Core Features & Use Cases
- Structured CIS benchmark evaluation (v2.1.0): Walks through all nine benchmark sections and assesses each recommendation against your available IaC/config evidence.
- Evidence-driven prioritized findings: Produces a prioritized report with recommendation IDs, severity, and remediation guidance mapped to specific CIS control IDs.
- Works across common Azure inputs: Reviews Terraform, Bicep, ARM templates, and configuration exports to evaluate Entra ID, NSG rules, Defender for Cloud settings, and Key Vault policies.
Quick Start
Run the azure-review skill against your Azure IaC directory by providing the target path so it generates a CIS v2.1.0 compliance report with prioritized remediation.