CNAPP — the unified posture score
CNAPP is not a separate engine. It is the unified view across everything Onam Security runs: seven pillars, each scored from the findings its engines produced, rolled into one posture score.
The seven pillars
| Pillar | What it scores |
|---|---|
| CSPM | Cloud configuration posture |
| CIEM | Identity and entitlement risk |
| CWPP | Workload protection |
| DSPM | Data security posture |
| Network | Network posture across the seven layers |
| Threat | Attack paths and MITRE-mapped activity |
| AppSec | SAST, DAST and SCA findings |
How scoring works
- Each pillar scores its own findings on a common 0–100 scale.
- Scores are weighted by severity and by exposure — a critical finding on an internet-reachable resource moves the score more than the same finding on an isolated one.
- Pillar scores roll into one overall score with a risk band, trended over time.
- Every score decomposes: score → pillar → finding → resource → remediation.
Because all pillars read the same findings model, the same resource is never counted twice or scored inconsistently between views.
Why the score moves when nothing changed
Because the estate changed. New resources are discovered continuously, and a newly deployed misconfigured resource lowers the score the same day it appears. Score history shows which findings caused any movement.
What is not in the score
Onam Estate and Onam FinOps are separate products and do not contribute to the CNAPP score. Folding a cost figure into a security score would make the number mean nothing.