Cloud

Secure IBM Cloud with cnspec

Scan IBM Cloud accounts against security and compliance best practices with cnspec.

Scan your IBM Cloud account to find security risks before they become incidents. cnspec evaluates IAM settings and policies, API keys, VPC networking, virtual server instances, Cloud Object Storage buckets, Key Protect and Hyper Protect Crypto Services keys, IBM Cloud Databases, Activity Tracker Event Routing, and Power Virtual Server workspaces across every VPC region, all without installing agents on your infrastructure.

New to cnspec? Read the Quickstart to install cnspec and run your first scan. To scan other platforms, see the cloud scanning overview.

Prerequisites

To scan IBM Cloud with cnspec, you must have:

Authenticate

cnspec authenticates with an IBM Cloud API key and only makes read calls. The identity that owns the key needs these access roles:

  • Viewer on IAM Identity, IAM Access Groups, and the other account management services you want to assess
  • Reader on VPC Infrastructure Services, Power Virtual Server, Key Protect, Activity Tracker Event Routing, and IBM Cloud Databases
  • Manager on Cloud Object Storage, which IBM Cloud requires to read a bucket's firewall and activity tracking settings

To create the key:

  1. Log in to the IBM Cloud console.
  2. Choose Manage > Access (IAM), then select API keys.
  3. Create a key for a user or service ID with the access above.
  4. Download the key file or copy the key. The console shows the key only once.

If you use the IBM Cloud CLI, you can create the key and write it to a file instead:

ibmcloud iam api-key-create cnspec-scan --file apikey.json

You can pass the key on the command line with --api-key, point cnspec at the downloaded file with --api-key-file, or export the key once and reuse it across commands:

export IBMCLOUD_API_KEY=your_api_key_here

This is the same variable the IBM Cloud CLI and SDKs read. cnspec also reads IC_API_KEY, the name the IBM Cloud Terraform provider uses.

Verify with a quick IBM Cloud check

Confirm that cnspec can reach your IBM Cloud account:

cnspec run ibm --api-key-file apikey.json -c 'ibm { accountId vpcRegions.length }'

If cnspec connects, it prints your account ID and the number of VPC regions it queries. If IAM doesn't accept the key, cnspec reports invalid IBM Cloud API key. Check the key, and check that IBM Cloud hasn't disabled it after detecting it as leaked.

Scan IBM Cloud

Scan your IBM Cloud account:

cnspec scan ibm

Or pass the key file explicitly:

cnspec scan ibm --api-key-file apikey.json

When the scan completes, cnspec prints each check with a pass or fail result and an overall risk score from 0 (no risk) to 100 (highest risk). To learn how to read a report in depth, see Understand Scan Results.

Limit the regions to scan

By default, cnspec queries VPC resources in every IBM Cloud region in parallel. To limit the scan to specific regions, use the --regions flag with a comma-separated list, or set the IBMCLOUD_REGIONS environment variable:

cnspec scan ibm --api-key-file apikey.json --regions us-south,eu-de

If a value doesn't match a region name, cnspec reports unknown IBM Cloud VPC region and lists the available regions.

Discover resources during a scan

cnspec connects to your IBM Cloud account as a single asset and, by default, also discovers its VPC virtual server instances, VPC security groups, and Power Virtual Server workspaces as their own assets. Use the --discover flag to choose which resource types become their own assets:

ValueDiscovers
autoEvery supported resource type
allEvery supported resource type
vpc-instancesVPC virtual server instances
vpc-security-groupsVPC security groups
power-workspacesPower Virtual Server workspaces
cnspec scan ibm --api-key-file apikey.json --discover power-workspaces

Filter resources by tag

Use the --filters flag to narrow scans to resources with specific tags. tags keeps resources that carry any of the listed tags, either as key:value or as a bare key to match the plain tag and any value of it. exclude:tags drops resources that carry any of the listed tags. Both user tags and access management tags count:

cnspec scan ibm --api-key-file apikey.json --filters tags=env:prod --filters exclude:tags=team:sandbox

The filters apply to discovered VPC instances, VPC security groups, and Power Virtual Server workspaces, and to the ibm.vpcInstances, ibm.vpcSecurityGroups, and ibm.powerWorkspaces lists in queries.

Write your own policies

Mondoo doesn't yet ship an out-of-the-box IBM Cloud policy, so use the checks below as a starting point and create your own policies to meet your specific requirements.

Asset model

The account is the root asset and reports the ibm-account platform. Discovered assets report ibm-vpc-instance, ibm-vpc-security-group, and ibm-power-workspace. Every IBM Cloud platform belongs to the ibm family.

Account-wide resources, such as IAM settings, access groups, policies, service IDs, API keys, trusted profiles, resource groups, and resource instances, are read once. VPC resources are collected from every VPC region and each one carries its region. If a region refuses a call, cnspec skips that region and still collects from the others. Power Virtual Server workspaces are found through the resource controller and queried in their own zone.

An empty list means the account has no such resources in the queried regions. A call that IBM Cloud refuses, for example because the key lacks a role, shows up as an error on that field rather than as an empty list.

Explore and test checks interactively

Open a cnspec shell to discover resources and try out checks:

cnspec shell ibm --api-key-file apikey.json

Review account IAM settings

cnspec> ibm.iamAccountSettings { mfa restrictCreateServiceId sessionExpirationInSeconds publicAccessEnabled }

A setting the account leaves at the IBM Cloud default (NOT_SET) reads as null.

Find policies that grant Administrator

cnspec> ibm.iamPolicies.where(roles.contains("Administrator")) { subjectAttributes resourceAttributes }

Find API keys that never expire

cnspec> ibm.iamApiKeys.where(expiresAt == null) { name iamId createdAt lastAuthentication }

Find security group rules open to the internet

cnspec> ibm.vpcSecurityGroups { name rules.where(direction == "inbound" && remoteCidr == "0.0.0.0/0") { protocol portMin portMax } }

Find instances without secure boot or with an HTTP metadata service

cnspec> ibm.vpcInstances.where(enableSecureBoot != true || metadataServiceProtocol != "https") { name region }

Find instances reachable from the internet

cnspec> ibm.vpcInstances.where(exposure.internetReachable) { name floatingIps { address } exposure { openIngressRules { protocol portMin portMax } } }

exposure combines the floating IPs bound to the instance's network interfaces with the inbound rules of their security groups that admit any address. It doesn't take network ACLs into account.

Find VPCs without an owner tag

cnspec> ibm.vpcs.where(tags.none(_ == /^owner:/)) { name region tags }

Find buckets without a customer managed key or activity tracking

cnspec> ibm.cosBuckets.where(!kmsEnabled || !activityTrackingManagementEvents) { name location kmsKey { name } }

Find root keys that don't rotate

cnspec> ibm.kmsKeys.where(!standardKey && !rotationEnabled) { name instance { name } registrations { resourceCrn } }

Check where audit events are routed

cnspec> ibm.atrackerRoutes { name rules { locations targets { name type writeStatus } } }

Find databases reachable from any address

cnspec> ibm.databases.where(publicEndpointEnabled && allowlist.length == 0) { name type version region }

List Power Virtual Server workspaces and their images

cnspec> ibm.powerWorkspaces { name zone images { name operatingSystem state } }

Learn more

On this page