Posture, spend & inventory
Overall posture
health score · vs. last month
Strong by design — we deployed this dashboard the way it grades. A short hardening backlog (tighten admin scope, add a CMK) is all that stands between us and an A.
Why this grade: No critical or high findings open — posture is solid.
3 low/medium items: deploy-role scope, audit access, KMS.
Multi-AZ Fargate behind an ALB; zero-downtime rolling deploys.
Entra SSO, no root use, MFA enforced; deploys via OIDC.
SOC 2 Type II in progress; Control Tower guardrails active.
Intune + Defender across a small, fully-managed fleet.
Serverless; ~$40/mo, no idle servers or NAT gateways.
Not enterprise-ready
0
Spend (MTD)
$41
Cloud resources
9
Devices compliant
67%
Servers compliant
—
Public-facing servers
0
Entra app hygiene — retiring what isn't used.
The highest-exposure findings, ranked by severity, internet reach, data sensitivity, privileged access & age.
AWS::IAM::Role · achieve-dashboard-deploy · us-east-1
AWS::SSO::PermissionSet · Achieve-Admins · us-east-1
AWS::KMS::Key · aws-controltower-logs · us-east-1
Audit readiness across the frameworks that matter to the business.
62/91 controls · Observation window Q4 2026
49/56 controls · audited Jun 27, 2026 · Clear the hardening backlog
Who can get in, and how well that access is controlled.
Update posture across cloud services, user devices, and servers.
0 of 0servers assessed — Azure & on-prem via Update Manager (Arc), AWS via Systems Manager Patch Manager.
Can we get the business back if something fails?
Last successful backup Jun 28, 2026.
The human layer — training and phishing resilience.
Critical & high-severity alerts from endpoint security and watched Teams channels.
No incidents in the current window. 🎉
Monitored workloads and your key services — live uptime and vendor status pages.
Findings, spend & resources across connected clouds.
The GitHub OIDC deploy role (achieve-dashboard-deploy) has AdministratorAccess; it only needs ECS/ECR/CloudFormation deploy permissions.
Fix: Replace AdministratorAccess with a least-privilege deploy policy.
AWS::IAM::Role · achieve-dashboard-deploy · us-east-1
since 2026-06-27
The Achieve-Admins group has AWSAdministratorAccess to the Audit and Log Archive accounts; Log Archive should be near-immutable.
Fix: Restrict standing human access; use break-glass for Log Archive.
AWS::SSO::PermissionSet · Achieve-Admins · us-east-1
since 2026-06-27
Org audit logs use AWS-managed (SSE-S3) encryption. A customer-managed key adds key control and a rotation policy.
Fix: Add a customer-managed KMS key for CloudTrail/Config in the Log Archive account.
AWS::KMS::Key · aws-controltower-logs · us-east-1
since 2026-06-27
vs $12 last month (+240%)
Active endpoints from Intune & Jamf (seen in the last 30 days), grouped by device class — encryption, EDR coverage, and patch status.
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
ACH-MBP-FOY C02ACHFOY01 | jfoy@achieve.llc | macOS 15.5 | Intune | FileVault: yes FileVault | EDR: yes Microsoft Defender | Updated: yes | today |
ACH-WIN-ENG-02 ACHW220ENG2 | eng@achieve.llc | Windows 11 24H2 | Intune | BitLocker: yes BitLocker | EDR: yes Microsoft Defender | Updated: yes | 1d ago |
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
ACH-IPHONE-FOY | jfoy@achieve.llc | iOS 18.5 | Intune | Data Protection: yes Data Protection | EDR: unknown | Updated: yes | 2d ago |
Cloud & on-prem hosts by environment — encryption, EDR, patch status, and public exposure.
No servers — this workload runs fully serverless. 🎉
How each workload is wired across AWS, Azure & GCP — internet-facing entry points down to data services.