Secure IBM Cloud with cnspec
Scan IBM Cloud accounts against security and compliance best practices with cnspec.
Scan your IBM Cloud account to find security risks before they become incidents. cnspec evaluates IAM settings and policies, API keys, VPC networking, virtual server instances, Cloud Object Storage buckets, Key Protect and Hyper Protect Crypto Services keys, IBM Cloud Databases, Activity Tracker Event Routing, and Power Virtual Server workspaces across every VPC region, all without installing agents on your infrastructure.
New to cnspec? Read the Quickstart to install cnspec and run your first scan. To scan other platforms, see the cloud scanning overview.
Prerequisites
To scan IBM Cloud with cnspec, you must have:
- cnspec installed on your workstation
- An IBM Cloud account
- An IBM Cloud API key
Authenticate
cnspec authenticates with an IBM Cloud API key and only makes read calls. The identity that owns the key needs these access roles:
- Viewer on IAM Identity, IAM Access Groups, and the other account management services you want to assess
- Reader on VPC Infrastructure Services, Power Virtual Server, Key Protect, Activity Tracker Event Routing, and IBM Cloud Databases
- Manager on Cloud Object Storage, which IBM Cloud requires to read a bucket's firewall and activity tracking settings
To create the key:
- Log in to the IBM Cloud console.
- Choose Manage > Access (IAM), then select API keys.
- Create a key for a user or service ID with the access above.
- Download the key file or copy the key. The console shows the key only once.
If you use the IBM Cloud CLI, you can create the key and write it to a file instead:
ibmcloud iam api-key-create cnspec-scan --file apikey.jsonYou can pass the key on the command line with --api-key, point cnspec at the downloaded file with --api-key-file, or export the key once and reuse it across commands:
export IBMCLOUD_API_KEY=your_api_key_hereThis is the same variable the IBM Cloud CLI and SDKs read. cnspec also reads IC_API_KEY, the name the IBM Cloud Terraform provider uses.
Verify with a quick IBM Cloud check
Confirm that cnspec can reach your IBM Cloud account:
cnspec run ibm --api-key-file apikey.json -c 'ibm { accountId vpcRegions.length }'If cnspec connects, it prints your account ID and the number of VPC regions it queries. If IAM doesn't accept the key, cnspec reports invalid IBM Cloud API key. Check the key, and check that IBM Cloud hasn't disabled it after detecting it as leaked.
Scan IBM Cloud
Scan your IBM Cloud account:
cnspec scan ibmOr pass the key file explicitly:
cnspec scan ibm --api-key-file apikey.jsonWhen the scan completes, cnspec prints each check with a pass or fail result and an overall risk score from 0 (no risk) to 100 (highest risk). To learn how to read a report in depth, see Understand Scan Results.
Limit the regions to scan
By default, cnspec queries VPC resources in every IBM Cloud region in parallel. To limit the scan to specific regions, use the --regions flag with a comma-separated list, or set the IBMCLOUD_REGIONS environment variable:
cnspec scan ibm --api-key-file apikey.json --regions us-south,eu-deIf a value doesn't match a region name, cnspec reports unknown IBM Cloud VPC region and lists the available regions.
Discover resources during a scan
cnspec connects to your IBM Cloud account as a single asset and, by default, also discovers its VPC virtual server instances, VPC security groups, and Power Virtual Server workspaces as their own assets. Use the --discover flag to choose which resource types become their own assets:
| Value | Discovers |
|---|---|
auto | Every supported resource type |
all | Every supported resource type |
vpc-instances | VPC virtual server instances |
vpc-security-groups | VPC security groups |
power-workspaces | Power Virtual Server workspaces |
cnspec scan ibm --api-key-file apikey.json --discover power-workspacesFilter resources by tag
Use the --filters flag to narrow scans to resources with specific tags. tags keeps resources that carry any of the listed tags, either as key:value or as a bare key to match the plain tag and any value of it. exclude:tags drops resources that carry any of the listed tags. Both user tags and access management tags count:
cnspec scan ibm --api-key-file apikey.json --filters tags=env:prod --filters exclude:tags=team:sandboxThe filters apply to discovered VPC instances, VPC security groups, and Power Virtual Server workspaces, and to the ibm.vpcInstances, ibm.vpcSecurityGroups, and ibm.powerWorkspaces lists in queries.
Write your own policies
Mondoo doesn't yet ship an out-of-the-box IBM Cloud policy, so use the checks below as a starting point and create your own policies to meet your specific requirements.
Asset model
The account is the root asset and reports the ibm-account platform. Discovered assets report ibm-vpc-instance, ibm-vpc-security-group, and ibm-power-workspace. Every IBM Cloud platform belongs to the ibm family.
Account-wide resources, such as IAM settings, access groups, policies, service IDs, API keys, trusted profiles, resource groups, and resource instances, are read once. VPC resources are collected from every VPC region and each one carries its region. If a region refuses a call, cnspec skips that region and still collects from the others. Power Virtual Server workspaces are found through the resource controller and queried in their own zone.
An empty list means the account has no such resources in the queried regions. A call that IBM Cloud refuses, for example because the key lacks a role, shows up as an error on that field rather than as an empty list.
Explore and test checks interactively
Open a cnspec shell to discover resources and try out checks:
cnspec shell ibm --api-key-file apikey.jsonReview account IAM settings
cnspec> ibm.iamAccountSettings { mfa restrictCreateServiceId sessionExpirationInSeconds publicAccessEnabled }A setting the account leaves at the IBM Cloud default (NOT_SET) reads as null.
Find policies that grant Administrator
cnspec> ibm.iamPolicies.where(roles.contains("Administrator")) { subjectAttributes resourceAttributes }Find API keys that never expire
cnspec> ibm.iamApiKeys.where(expiresAt == null) { name iamId createdAt lastAuthentication }Find security group rules open to the internet
cnspec> ibm.vpcSecurityGroups { name rules.where(direction == "inbound" && remoteCidr == "0.0.0.0/0") { protocol portMin portMax } }Find instances without secure boot or with an HTTP metadata service
cnspec> ibm.vpcInstances.where(enableSecureBoot != true || metadataServiceProtocol != "https") { name region }Find instances reachable from the internet
cnspec> ibm.vpcInstances.where(exposure.internetReachable) { name floatingIps { address } exposure { openIngressRules { protocol portMin portMax } } }exposure combines the floating IPs bound to the instance's network interfaces with the inbound rules of their security groups that admit any address. It doesn't take network ACLs into account.
Find VPCs without an owner tag
cnspec> ibm.vpcs.where(tags.none(_ == /^owner:/)) { name region tags }Find buckets without a customer managed key or activity tracking
cnspec> ibm.cosBuckets.where(!kmsEnabled || !activityTrackingManagementEvents) { name location kmsKey { name } }Find root keys that don't rotate
cnspec> ibm.kmsKeys.where(!standardKey && !rotationEnabled) { name instance { name } registrations { resourceCrn } }Check where audit events are routed
cnspec> ibm.atrackerRoutes { name rules { locations targets { name type writeStatus } } }Find databases reachable from any address
cnspec> ibm.databases.where(publicEndpointEnabled && allowlist.length == 0) { name type version region }List Power Virtual Server workspaces and their images
cnspec> ibm.powerWorkspaces { name zone images { name operatingSystem state } }Learn more
- IBM Cloud Resource Pack Reference: every IBM Cloud resource and field cnspec can query
- Write Effective MQL: a guide to authoring checks and queries