Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - willj4945/cloudcomply · GitHub
Skip to content

Repository files navigation

cloudcomply

A lightweight, interactive CLI/TUI for assessing AWS Organizations against NIST SP 800-53 controls. Designed to run directly in AWS CloudShell with zero installation — drop in a single static binary and go.

GoLicense


Features

  • Org-wide visibility — enumerate all accounts and OUs across an AWS Organization
  • NIST 800-53 compliance scoring — aggregated findings from AWS Security Hub mapped to control families (AC, AU, CM, IA, SC, SI, and more)
  • Interactive findings browser — filter by control family, see pass/fail status, severity, and accounts affected
  • RMF alignment — findings tagged to the relevant RMF step (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • DoD Cloud Computing SRG Impact Level filtering — filter findings and view a compliance score scoped to the minimum DoD CC SRG Impact Level (IL2/IL4/IL5/IL6) a Mission Owner (MO) is targeting
  • Threat modeling — guided wizard to generate STRIDE-based threat models for AWS workloads (coming soon)
  • Best practices report — custom checks beyond Security Hub standards (coming soon)
  • Export-ready — Markdown and JSON output suitable for ATO evidence packages (coming soon)
  • Demo mode — realistic fake data for offline use, demos, and portfolio showcases

Quick Start

Run in AWS CloudShell (recommended)

Download the latest static Linux binary from Releases and run it directly — no Go installation needed:

curl -LO https://github.com/yourname/cloudcomply/releases/latest/download/cloudcomply-linux-amd64
chmod +x cloudcomply-linux-amd64
./cloudcomply-linux-amd64

Build from source

Requires Go 1.21+.

git clone https://github.com/yourname/cloudcomply.git
cd cloudcomply
go build -ldflags="-s -w" -o cloudcomply .
./cloudcomply

Cross-compile a static binary for CloudShell

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o cloudcomply-linux-amd64 .

See CLI.md for the full command reference, including headless report nist usage for CI/scripting.


Navigation

KeyAction
/ kMove up
/ jMove down
/ hPrevious control family filter
/ lNext control family filter
[Previous DoD SRG impact level filter
]Next DoD SRG impact level filter
EnterSelect / open
Esc / qBack / quit
Ctrl+CForce quit

AWS Permissions

The tool requires read-only access. Run from a role in your Security Hub delegated admin account with at minimum:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"securityhub:GetFindings",
"securityhub:GetFindingStatistics",
"securityhub:ListFindingAggregators",
"organizations:ListAccounts",
"organizations:ListOrganizationalUnitsForParent",
"organizations:DescribeOrganization",
"sts:GetCallerIdentity"
],
"Resource": "*"
}
]
}

For cross-account checks: add sts:AssumeRole and a trust policy in member accounts.


Project Status

FeatureStatus
Dashboard + NIST compliance score✅ Done
Findings browser (with family filter)✅ Done
Demo mode (realistic fake data)✅ Done
Cobra CLI command structure✅ Done
Live Security Hub integration🔲 Planned
Threat modeling wizard🔲 Planned
Best practices custom checks🔲 Planned
Markdown / JSON report export🔲 Planned

Tech Stack


NIST / RMF Mapping

Findings are mapped to NIST SP 800-53 Rev. 5 control families and tagged to the relevant RMF step, making them directly usable as evidence in an ATO package.

Control FamilyCoverage
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
IA — Identification and Authentication
SC — System and Communications Protection
SI — System and Information Integrity
Additional familiesPlanned

DoD Cloud Computing SRG Impact Levels

Each finding is tagged with the lowest DoD Cloud Computing Security Requirements Guide (SRG) Impact Level at which it's required, so a Mission Owner (MO) can score compliance against the specific IL they're targeting rather than the full control catalog. Levels are cumulative — a control required at IL2 is also in scope at IL4/IL5/IL6.

Impact LevelTypical Data Sensitivity
IL2Non-controlled unclassified information (public/low-sensitivity)
IL4Controlled Unclassified Information (CUI)
IL5Higher-sensitivity CUI and National Security Systems
IL6Classified information up to SECRET

The dashboard shows a compliance score scoped to a target Impact Level, and the findings browser lets you filter to only the controls in scope for that level ([ / ] to cycle levels).


License

MIT

About

No description, website, or topics provided.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages