Get a Demo
Under Attack?
Flowchart depicting a sequence of icons connected by lines. Elements include a globe, servers, a warning symbol, and symbols representing AWS Lambda, bugs, and GitHub logos. Arrows indicate data pathways between these components.

Bake-In Cloud Security Compliance with the Upwind Posture Framework

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur June 24, 2024

Bake-In Cloud Security Compliance with the Upwind Posture Framework

Security practitioners are no strangers to posture security control frameworks, such as the Center for Internet Security (CIS), the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the System and Organization Controls (SOC). Each framework is recognized as a standard for security posture compliance and serves as a structured guideline for securing information systems, each tailored to specific regulatory or technological needs.

By adhering to these frameworks or using them as a guide to enhance your security efforts, you can ensure compliance, and build trust among stakeholders by setting and maintaining high standards of data protection and operational control in the cloud. However, the organizations & agencies that maintain these frameworks often struggle to keep pace with evolving cyber security threats and attacks, or to exhaustively cover the depth of controls that advanced organizations expect. Updates to these frameworks can be infrequent, and the guidelines, while comprehensive, may not account for the complexities in a more sophisticated organization’s environment. 

For this reason, we are excited to announce a major enhancement to the Upwind Cloud Security Platform’s posture module: the Upwind Posture Framework

The Upwind Posture Framework

The Upwind posture framework is designed to set a new standard in security frameworks, bridging critical security gaps and offering continually updated controls that cover a broad spectrum of areas and cloud providers. 

Screenshot-2024-06-20-at-5.48.24%E2%80%AFAM-1024x492

We built the Upwind Framework based on our extensive feedback from Upwind customers, along with research and with customization by our industry-leading security research team. The Upwind Framework is designed to be a continually evolving framework that will consistently keep pace with the threat landscape and go beyond the security controls in other industry frameworks.

The Upwind Framework focuses on emerging and often overlooked security risks, giving you the ability to adapt to changes, ensure superior security posture protection and streamline proactive posture security adoption. This approach gives you the ability to easily employ the most advanced defense strategies available and strengthen your overall cloud security resilience while maintaining compliance and auditability with existing industry standards.

What Does the Upwind Posture Framework Include? 

The Upwind Posture Framework is dynamic and constantly updated, designed to address advanced and evolving posture risks that the Upwind security research team continuously monitors.

6-External-exposure-1024x873

The set of controls available in the Upwind Posture Framework’s initial release focus on immediately addressing gaps that are overlooked by other frameworks, offering robust controls to identify external exposures for AWS.

The Upwind Posture Framework’s initial release offers controls for external exposures across AWS services, including:

  • S3 Buckets
  • DNS settings
  • Lambda functions
  • Amazon Simple Queue Service (SQS)
  • Amazon Simple Notification Service (SNS) 
  • SageMaker
  • EMR clusters

The Upwind Posture Framework will be frequently updated to include additional controls and directly address emerging advanced security threats. This initial release offers comprehensive coverage against advanced threats in AWS, and future iterations will also include additional controls for Google Cloud and Azure. 

Learn More

To learn more about the Upwind Posture Framework and Upwind’s CSPM capabilities visit the Upwind Documentation Center (login required), or request a demo.

Contents

Further Reading

ArgoCD repoURL XSS

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover (CVE-2026-62341)

Executive Summary  CVE-2026-62341 is a stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.6] that lets an attacker who can create or modify an Application persist a malicious repoURL, which then executes in an administrator's browser inside the ArgoCD origin. Because the payload rides the admin's authenticated session, and because ArgoCD's controller typically runs…
The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS