Subscribing to Policy Packs
Policy Packs are curated rule bundles maintained by Troposphere for well-known compliance frameworks. Subscribing an organisation to a pack enables every rule in it, and subsequent syncs evaluate your resources against those rules alongside any custom policies you have authored.
See the Policy Packs concept for background on how packs fit alongside custom policies.
Subscribing to a pack
- Navigate to Policies > Overview in the sidebar.
- Locate the Compliance Packs card on the page and click Manage in its header.
- The Compliance Packs dialog lists every pack available to your organisation. For each pack you will see:
- Name and framework badge (for example, CIS Azure Benchmark v2.0 with a
CISbadge). - A short description of what the pack covers.
- The pack’s version, rule count, and the cloud providers it applies to.
- Name and framework badge (for example, CIS Azure Benchmark v2.0 with a
- Click Subscribe on any pack you want to enable. Subscribed packs are highlighted and marked with a Subscribed indicator.
- Close the dialog when you are done. Subsequent syncs will begin evaluating your resources against the pack’s rules.
Note
Pack rules are maintained by Troposphere and cannot be edited by your organisation. If you need to deviate from a pack, keep the subscription active for most rules and author a custom policy that covers the exception.
Unsubscribing
To stop enforcing a pack, open the same Compliance Packs dialog and click Unsubscribe on the pack you want to remove. The pack’s rules will no longer produce new alerts on subsequent syncs.
Where subscribed packs appear
Once a subscription is active:
- Violations from the pack’s rules show up on the Alerts page as Policy-type alerts, with the rule’s severity driving the alert severity.
- The Compliance Packs card on the Policies Overview page shows a quick summary of every active subscription along with its current open-violation count.
- Each pack rule carries a compliance reference (for example,
CIS 6.2orHIPAA §164.312(a)(2)(iv)) that appears alongside the violation so you can map findings back to the framework requirement they originate from.