DSPM findings reference
Every DSPM check: what it looks at, what passes, and the severity when a data store fails it. AWS severities shown; other clouds follow the same model.
Each store is evaluated against the checks below on every scan. Rule identifiers follow the pattern <cloud>.dspm.<check>.<store type> — for example aws.dspm.encryption_posture.s3_bucket. Every finding carries the store's classification labels, so findings can be filtered to sensitive stores only.
Per-store checks
| Check | Looks at | Passes when | Severity on failure (AWS) |
|---|---|---|---|
| Classification | Name, description, tags | No sensitive label is inferred — a labelled store is a finding so it can be reviewed | High |
| Encryption posture | Store encryption setting | Encryption at rest is on | Critical — S3 buckets, RDS · High — DynamoDB, Redshift, OpenSearch, Glue |
| Access control | Public grants, provider public flag | No grant makes the store public | Critical — public S3 bucket or public RDS · High — DynamoDB, Redshift |
| Data residency | Region | Region is inside the allowed set | Medium |
| Activity logging | Access or audit logging | Logging is on | High — S3, RDS · Medium — DynamoDB, Redshift, OpenSearch |
| Lifecycle and backup | Versioning, lifecycle, retention, point-in-time restore | The relevant protection is on | High — RDS · Medium — S3, DynamoDB · Low — Redshift |
| Lineage | Event notifications, stream consumers | Always passes — informational | — |
| Governance score | Encryption, public exposure, logging | Score is 80 or more | High below 50 · Medium otherwise |
Account- and grant-level checks (AWS)
| Rule | Severity |
|---|---|
aws.s3.bucket.no_cross_account_write_access — another account can write | Critical |
aws.s3.bucket.cross_account_read_access_reviewed — another account can read | High; critical if object reads were seen in the last 24 hours |
aws.s3.bucket.cross_account_replication_reviewed — another account has policy actions | High |
aws.s3.bucket.bucket_owner_enforced — object ownership is not owner-enforced | Medium |
| Lake Formation broad default or wildcard admin grants | Per rule |
Kubernetes
ConfigMaps with credential-like key names are classification findings (high); every Secret is labelled confidential. ConfigMaps are not encrypted at rest by default. Under access control, a Secret in the default namespace is high (medium elsewhere), and a credential-bearing ConfigMap in default is high.
Posture rules mapped to data security
Separately from the checks above, posture rules that carry data-security metadata are grouped into DSPM modules — encryption, access governance, activity monitoring, residency, compliance and classification — with GDPR, HIPAA and PCI DSS references where the rule defines them. They appear in the same findings list.
Where findings go
- The Data Security findings view, filterable by label, module and severity.
- The shared findings list and compliance mapping, alongside every other engine.
- The security graph, for attack paths — see Access mapping.