Onam Security

DSPM findings reference

Every DSPM check: what it looks at, what passes, and the severity when a data store fails it. AWS severities shown; other clouds follow the same model.

Each store is evaluated against the checks below on every scan. Rule identifiers follow the pattern <cloud>.dspm.<check>.<store type> — for example aws.dspm.encryption_posture.s3_bucket. Every finding carries the store's classification labels, so findings can be filtered to sensitive stores only.

Per-store checks

CheckLooks atPasses whenSeverity on failure (AWS)
ClassificationName, description, tagsNo sensitive label is inferred — a labelled store is a finding so it can be reviewedHigh
Encryption postureStore encryption settingEncryption at rest is onCritical — S3 buckets, RDS · High — DynamoDB, Redshift, OpenSearch, Glue
Access controlPublic grants, provider public flagNo grant makes the store publicCritical — public S3 bucket or public RDS · High — DynamoDB, Redshift
Data residencyRegionRegion is inside the allowed setMedium
Activity loggingAccess or audit loggingLogging is onHigh — S3, RDS · Medium — DynamoDB, Redshift, OpenSearch
Lifecycle and backupVersioning, lifecycle, retention, point-in-time restoreThe relevant protection is onHigh — RDS · Medium — S3, DynamoDB · Low — Redshift
LineageEvent notifications, stream consumersAlways passes — informational—
Governance scoreEncryption, public exposure, loggingScore is 80 or moreHigh below 50 · Medium otherwise

Account- and grant-level checks (AWS)

RuleSeverity
aws.s3.bucket.no_cross_account_write_access — another account can writeCritical
aws.s3.bucket.cross_account_read_access_reviewed — another account can readHigh; critical if object reads were seen in the last 24 hours
aws.s3.bucket.cross_account_replication_reviewed — another account has policy actionsHigh
aws.s3.bucket.bucket_owner_enforced — object ownership is not owner-enforcedMedium
Lake Formation broad default or wildcard admin grantsPer rule

Kubernetes

ConfigMaps with credential-like key names are classification findings (high); every Secret is labelled confidential. ConfigMaps are not encrypted at rest by default. Under access control, a Secret in the default namespace is high (medium elsewhere), and a credential-bearing ConfigMap in default is high.

Posture rules mapped to data security

Separately from the checks above, posture rules that carry data-security metadata are grouped into DSPM modules — encryption, access governance, activity monitoring, residency, compliance and classification — with GDPR, HIPAA and PCI DSS references where the rule defines them. They appear in the same findings list.

Where findings go

  • The Data Security findings view, filterable by label, module and severity.
  • The shared findings list and compliance mapping, alongside every other engine.
  • The security graph, for attack paths — see Access mapping.