TotalCloud Release 2.28

September 28, 2026

Qualys TotalCloud 2.28.0 introduces AI-powered remediation for posture findings, dynamic tagging across Inventory and Posture, and expanded inventory coverage for AWS and Azure. This release also adds interactive posture health charts, improved discovery and reconciliation for Azure VMSS, customizable CSV reports, and extended CIS AWS Benchmark coverage.

Dynamic Tagging across Inventory and Posture

Applicable for:  aws azure gcp oci

TotalCloud now supports dynamic tagging across all inventory resources, using the same tag-rule workflow available in other Qualys products. A dynamic tag is driven by a query rather than a fixed value, so as your cloud environment changes, TotalCloud automatically tags every matching resource with no manual re-tagging.

Key Features

  • Tag rules powered by Qualys Query Language (QQL), the same query language used elsewhere in TotalCloud.
  • TotalCloud added as a Tag Rule selection in the Create/Edit Tag workflow.
  • Query validation against live inventory before a rule is saved.
  • Dynamic tags appear alongside existing tags across Inventory, and Posture.

Create a dynamic tag rule in Configure > Tags, or via the quick actions menu on a Policy. Enter the details, select TotalCloud as the Tag Rule, choose cloud providers, enter and validate the QQL query, then create the new dynamic tag.

Create Tag panel with TotalCloud selected as the tag engine and a cloud provider and query field displayed

Streamline Your CSPM Reports with Custom Column Selection

Applicable for:  aws azure gcp oci

TotalCloud now offers flexibility on CSPM reporting by enhancing the entire report generation process. You can now select which section to add to the downloaded report and also choose the exact attributes you need as columns on csv file, hence avoiding download of non-relevant section and information. A new Report Display step lets you turn sections and individual columns on or off, so the report matches what your team actually reviews.

You can now choose from five customization sections.

  1. Overall Compliance Score
  2. Account-level statistics
  3. Control-level statistics
  4. Resource-level statistics (is displayed when "Resource Summary" is turned on)
  5. Details

Benefits:

  • Reports match how your team works, rather than a single fixed layout for everyone.
  • Smaller, focused CSVs are easier to open, filter, and feed into other tools.
  • New ID fields make it easier to cross-reference resources and controls.

customize your CSPM reports

Currently, runtime scans support CSV reports. Support for PDF and build-time reports, as well as fields like tags and remediation steps, is not available.

Interactive Visual Charts for Instant Posture Health Visibility

Applicable for:  aws azure gcp oci

The Cloud Inventory Overview now visualizes posture issues for each connected cloud platform, AWS, Azure, GCP, and Oracle Cloud Infrastructure, as a color-coded donut chart, replacing the previous plain summary card. This gives you an immediate visual read on the posture health of all your connected clouds from a single page.

Key Features

  • Color-coded donut chart per cloud platform: green for resources that passed posture checks, red for resources with posture issues.
  • The percentage in the center of the chart shows the share of failed resources among all resources discovered on that platform.
  • On hover, the green arc displays the exact count of passed resources, and the red arc displays the exact count of failed resources.

Extended Inventory Coverage

Applicable for: aws azure

We have expanded our cloud security coverage by adding support for additional AWS resource types in Cloud Inventory, enabling discovery, inventory, and security posture assessment across a broader range of cloud services.

The resources are as follows:

Platform Resource Permissions
AWS AWS EBS Encryption ec2:GetEbsEncryptionByDefault
ec2:GetEbsDefaultKmsKeyId
kms:DescribeKey
AWS GuardDuty Detector guardduty:ListDetectors
guardduty:GetDetector
guardduty:ListTagsForResource
AWS IAM Account Summary iam:GetAccountSummary
AWS S3 Block Public Access Settings s3:GetPublicAccessBlock
s3:GetAccountPublicAccessBlock
AWS SSM Service Setting ssm:GetServiceSetting
AWS WAF Global Rule Group wafv2:ListRuleGroups
wafv2:GetRuleGroup
AWS WAF Rule Group wafv2:ListRuleGroups
wafv2:GetRuleGroup
AWS WAF V2 Global Web ACL wafv2:ListWebACLs
wafv2:GetWebACL
AWS WAF V2 Web ACL Resource wafv2:ListWebACLs
wafv2:GetWebACL
CloudWatch Alarm cloudwatch:DescribeAlarms
CloudWatch LogGroup logs:DescribeLogGroups
EC2 Elastic IP Address ec2:DescribeAddresses
EC2 NAT Gateway ec2:DescribeAddresses
ec2:DescribeNatGateways
Elastic Beanstalk Environment elasticbeanstalk:DescribeEnvironments
Elasticache Cluster elasticache:DescribeCacheClusters
Glue Crawler glue:ListCrawlers
glue:GetCrawler
Glue ETL Job glue:ListJobs
glue:GetJobs
IAM SAML Provider iam:ListSAMLProviders
iam:GetSAMLProvider
Kinesis Firehose Delivery Stream firehose:ListDeliveryStreams
firehose:DescribeDeliveryStream
Network Firewall Rule Groups network-firewall:ListRuleGroups
network-firewall:DescribeRuleGroup

Additionally, we have improved the following resource to include more details:

  • AWS: IAM User (new Virtual MFA Devices tab added).
  • Azure: API App, Web App, Function App, Logic App (new Configurations tab added)
  • GCP:  Detailed inventory support added for resources, including Instance Groups, Buckets, Topics, Disks, Spanner Databases, Instance Templates, Cloud Armor Policies, Cryptographic Keys, Datasets, Artifact Registry Repositories, Disk Snapshots, Dataproc Clusters, BigTable Instances, Disk Images, Kubernetes Nodes, Instances, Service Accounts, and Cloud DNS Zones.

Extended CIS Benchmark Coverage

Applicable for:  aws 

TotalCloud now extends compliance coverage with support for the following CIS Amazon Web Services Benchmarks:

  • CIS Amazon Web Services Compute Services Benchmark v2.0.0
  • CIS Amazon Web Services Database Services Benchmark v2.0.0
  • CIS Amazon Web Services End User Compute Services Benchmark v1.2.0
  • CIS Amazon Web Services Storage Services Benchmark v1.0.0

This is in addition to TotalCloud's existing support for the CIS Amazon Web Services Foundations Benchmark, AWS Database Services best practices, and other supported policies.

Control Updates

New controls in CIS AWS Compute Services Benchmark Policy

Applicable for: aws

Platform CID Title Service Resource Criticality
AWS 741 Ensure Amazon ECS task definitions using host network mode do not allow privileged or root user access to the host ECS ECS task definition High
AWS 742 Ensure Amazon ECS task definitions do not have privileged set to true ECS ECS task definition High
AWS 743 Ensure the readonlyRootFilesystem parameter is enabled in Amazon ECS task definitions to restrict write access to the filesystem ECS ECS task definition Medium
AWS 744 Ensure secrets are not passed as container environment variables in Amazon ECS task definitions ECS ECS task definition High
AWS 745 Ensure Amazon ECS Fargate services are using the latest Fargate platform version ECS ECS service Medium
AWS 746 Ensure Amazon ECS services are tagged ECS ECS service Low
AWS 747 Ensure Amazon ECS clusters are tagged ECS ECS cluster Low
AWS 748 Ensure Amazon ECS task definitions are tagged ECS ECS task definition Low
AWS 749 Ensure only trusted images are used with Amazon ECS ECS ECS task definition High
AWS 750 Ensure assignPublicIp is set to DISABLED for Amazon ECS task sets ECS ECS service High
AWS 751 Ensure customer-managed keys are used to encrypt AWS Fargate ephemeral storage data for Amazon ECS ECS ECS cluster Medium

See Control Permissions for AWS to understand the permissions needed for the new controls.

New controls in CIS AWS End User Compute Services Benchmark Policy

Applicable for: aws

Platform CID Title Service Resource Criticality
AWS 752 Ensure the default IP access control group is disassociated for WorkSpaces directories in all regions Workspace Directory Medium
AWS 754 Ensure WorkSpaces that are not being utilized are removed Workspace Workspace Medium
AWS 755 Ensure primary interface ports for Workspaces are not open to all inbound traffic Workspace Workspace High
AWS 757 Ensure AppStream 2.0 fleet maximum session duration is set to 10 hours (36000 seconds) or less AppStream AppStream Fleet Medium
AWS 758 Ensure AppStream 2.0 fleet disconnect timeout is set to 5 minutes (300 seconds) or less AppStream AppStream Fleet Medium
AWS 759 Ensure AppStream 2.0 fleet idle disconnect timeout is set to 10 minutes (600 seconds) or less and is not disabled AppStream AppStream Fleet Medium
AWS 760 Ensure AppStream 2.0 fleet default internet access is disabled AppStream AppStream Fleet High

See Control Permissions for AWS to understand the permissions needed for the new controls.

New controls in CIS AWS Storage Services Benchmark Policy

Applicable for: aws

Platform CID Title Service Resource Criticality
AWS 6 Ensure that custom IAM Password Policy is Defined IAM IAM Password Policy High
AWS 7 Ensure that custom IAM password policy requires at least one uppercase letter IAM IAM Password Policy High
AWS 8 Ensure that custom IAM password policy requires at least one lowercase letter IAM IAM Password Policy High
AWS 9 Ensure that custom IAM password policy requires at least one symbol IAM IAM Password Policy High
AWS 10 Ensure that custom IAM password policy requires at least one number IAM IAM Password Policy High
AWS 11 Ensure that custom IAM password policy requires minimum length of 14 or greater IAM IAM Password Policy High
AWS 12 Ensure that custom IAM password policy prevents password reuse IAM IAM Password Policy High
AWS 13 Ensure that custom IAM password policy expires passwords within 90 days or less IAM IAM Password Policy High
AWS 50 Ensure IAM policies that allow full '*:*' administrative privileges are not attached IAM IAM Policy High
AWS 433 Ensure IAM instance roles are used for AWS resource access from instances EC2 EC2 Instance Medium
AWS 576 Ensure EFS access points should enforce a root directory EFS EFS Access Point High
AWS 577 Ensure EFS Access Points should enforce a POSIX user identity EFS EFS Access Point High
AWS 719 Ensure that VPC security groups do not allow unrestricted access on all ports VPC VPC Security Group High

See Control Permissions for AWS to understand the permissions needed for the new controls.

New controls in CIS AWS Database Services Benchmark Policy

Applicable for: aws

Platform CID Title Service Resource Criticality
AWS 50 Ensure IAM policies that allow full '*:*' administrative privileges are not attached IAM IAM Policy High
AWS 53 Ensure encryption-at-rest is enabled for Relational Database Service (RDS) Instances RDS RDS High
AWS 55 Ensure Auto Minor Version Upgrade feature is Enabled for Relational Database Service (RDS) Instances RDS RDS Medium
AWS 78 Ensure public access is not given to Relational Database Service (RDS) Instance RDS RDS High
AWS 88 Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS RDS RDS Medium
AWS 356 Ensure that Amazon ElastiCache Redis clusters have automatic backup turned on ElastiCache Redis Medium
AWS 408 Ensure that DocumentDB Clusters are encrypted with KMS using a customer managed Key (CMK) DocumentDB DocumentDB Clusters High
AWS 543 Ensure DynamoDB table should have deletion protection enabled DynamoDB DynamoDB Table Medium
AWS 544 Ensure DynamoDB Accelerator cluster should be encrypted in transit DynamoDB DAX Cluster Medium
AWS 581 Ensure that AWS ElastiCache Redis standalone clusters should have automatic minor version upgrade enabled ElastiCache Redis Medium

See Control Permissions for AWS to understand the permissions needed for the new controls.

New Controls for Azure (Available for Policy Attachment)

Applicable for: azure

Platform CID Title Service Resource Criticality
Azure 50688 Ensure that an activity log alert is created for Create or Update PostgreSQL Flexible Server events Monitor Activity log alert Medium
Azure 50689 Ensure that an activity log alert is created for Delete PostgreSQL Flexible Server events Monitor Activity log alert Medium
Azure 50690 Ensure that an activity log alert is created for Create or Update MySQL Flexible Server events Monitor Activity log alert Medium
Azure 50691 Ensure that an activity log alert is created for Delete MySQL Flexible Server events Monitor Activity log alert Medium

See Control Permissions for Azure to understand the permissions needed for the new controls.

Controls Migration

Applicable for: aws

Platform CID Title Old Policy New Policy
AWS 51 Ensure that Public Accessibility is set to No for Database Instances AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 69 Ensure automated backups are enabled for Relational Database Service (RDS) database instances AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 70 Ensure Deletion Protection is enabled for Relational Database Service (RDS) Database Cluster AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 71 Ensure Deletion Protection is enabled for Relational Database Service (RDS) Database instances AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 72 Ensure IAM Database Authentication is Enabled for the Database (DB) Cluster AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 73 Ensure IAM Database Authentication is Enabled for the Database (DB) Instances AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 74 Ensure Relational Database Service (RDS) Log Exports is enabled for Database (DB) Cluster AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 75 Ensure Relational Database Service (RDS) Log Exports is enabled for Database (DB) Instances AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 81 Ensure Relational Database Service (RDS) Microsoft SQL instance enforces encrypted connections only AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 82 Ensure Relational Database Service (RDS) PostgreSQL instance enforces encrypted connections only AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 83 Ensure Relational Database Service (RDS) PostgreSQL Cluster enforces encrypted connections only AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 84 Ensure Encryption is enabled for the Relational Database Service (RDS) database Cluster AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 86 Ensure Customer Managed Key (CMK) is used to protect Relational Database Service (RDS) database Cluster encryption key AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 89 Ensure database cluster replication is set to the another zone for High Availability AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 91 Ensure Enhance monitoring is enabled for Relational Database Service (RDS) Database Instance AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 126 Ensure Amazon Machine Images (AMIs) owned by account are encrypted AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 127 Ensure Elastic Block Store (EBS) volume snapshots are encrypted AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 133 Ensure backup retention is set to minimum of 7 days for DocumentDB clusters AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 134 Ensure audit logs is enabled for Log export to CloudWatch for DocumentDB clusters AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 135 Ensure deletion protection is enabled for DocumentDB clusters AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 139 Ensure IAM DB authentication is enabled for neptune database AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 141 Ensure Audit logs is enabled for log exports to cloudwatch for neptune database AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 143 Ensure deletion protection is enabled for neptune DB AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 146 Ensure that AWS Elastic Block Store (EBS) volume snapshots are not public AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 147 Ensure that AWS ElastiCache Memcached clusters are not associated with default VPC AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 148 Ensure that AWS ElastiCache Redis clusters are not associated with default VPC AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 151 Ensure AWS ElastiCache Redis cluster with Multi-AZ Automatic Failover feature is set to enabled AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 152 Ensure AWS ElastiCache Redis cluster with Redis AUTH feature is enabled AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 153 Ensure that AWS ElastiCache Redis clusters are In-Transit encrypted AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 154 Ensure that AWS ElastiCache Redis clusters are Data At-Rest encrypted AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 155 Ensure that AWS ElastiCache Redis clusters are Data At-Rest encrypted with CMK AWS Best Practices Policy CIS AWS Database Services Benchmark
AWS 169 Ensure DynamoDB tables are encrypted using KMS Customer managed Keys AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 181 Ensure proper protocol is configured for Radius server in AWS Directory AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 197 Ensure to encrypt the User Volumes and Root Volumes with the customer managed master keys for AWS WorkSpace AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 198 Ensure Workspace directory must have a vpc endpoint so that the API traffic associated with the management of workspaces stays within the vpc AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 204 Ensure AWS EBS Volume snapshots are encrypted with KMS using a customer managed Key (CMK) AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 211 Ensure Maintenance Mode is not enabled in Workspace Directories AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 214 Ensure Device Type Web Access Control is allowed in Workspace Directories AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 219 Ensure neptune DB snapshots are encrypted AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 225 Ensure to enable the encryption of the Root volumes for Workspaces in all regions AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 226 Ensure to enable the encryption of the User volumes for Workspaces in all regions AWS Best Practices Policy CIS AWS End User Compute Services Benchmark
AWS 292 Ensure Dynamodb point in time recovery (backup) is enabled AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 312 Ensure container insights are enabled on ECS cluster AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 330 Ensure DocDB TLS is not disabled AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 350 Ensure that detailed monitoring is enabled for EC2 instances AWS Best Practices Policy CIS AWS Storage Services Benchmark
AWS 370 Ensure that Auto Scaling Groups supply tags to Launch Configurations AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 411 Ensure that a log driver has been defined for each active Amazon ECS task definition AWS Best Practices Policy CIS AWS Compute Services Benchmark
AWS 453 Ensure to block public access to Amazon EFS file systems AWS Best Practices Policy CIS AWS Storage Services Benchmark
AWS 507 Ensure encryption at rest is enabled for AWS DocumentDB clusters AWS Database Service Best Practices CIS AWS Database Services Benchmark
AWS 538 Ensure that Images (AMIs) are not older than 90 days AWS Best Practices Policy CIS AWS Compute Services Benchmark

Issues Addressed

Applicable for: aws azure gcp oci

We fixed the following important and notable issues in this release.

Category/Component Issue
CV - False Positive CID-50382 and CID-50384 are based on Azure Database for PostgreSQL - Single Server, which Microsoft has now deprecated, leading some customers to question why these controls are still active. Both controls continue to evaluate any existing PostgreSQL Single Server resources still running in an environment, so we are not deprecating them currently. To cover the replacement service, we have also added four new controls for PostgreSQL Flexible Server and MySQL Flexible Server activity log alerts.
CID 26 and related CIDs were incorrectly flagged as failing because the control was evaluating all AWS KMS key types instead of only customer-managed keys (CMKs). Corrected the control logic to evaluate CMKs only, resolving the false positive.
CID 426 was reporting FAIL for Network Load Balancers even when a WAF was correctly attached. The issue was caused by throttling from repeated GET calls, which produced inconsistent resource counts during evaluation. Updated the control's evaluation logic to handle throttled responses correctly, resolving the false positive.
CID 40103 (Ensure OCI IAM credentials unused for 45 days or more are disabled) was incorrectly flagging deactivated IAM users as FAIL, resulting in false visibility. Enhanced the control logic to correctly account for deactivated users, resolving the false positive.
TotalCloud - Connectors The AWS connector was missing the apigateway:GET permission for :aws:apigateway:*::/domainnames/*, which could prevent API Gateway custom domain name resources from being evaluated correctly. Corrected the connector's permission set to include this permission.
TotalCloud - UI GCP Cloud SQL instance controls have been showing inconsistent evidences in reports/UI, it was due to evidence data was missing during evaluation. Fixed that by adding all mandatory evidences providing consistency, so all Cloud SQL instance controls now capture and report evidence consistently.