Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
@article{208799,
author = {Sushant Santosh Khot and Guna Dhondwad},
title = {Compliance-Aware, Human-Gated Cloud Remediation: An LLM-Augmented, Specificity-Scored Framework for Multi-Jurisdictional Cloud Security Posture Management},
journal = {International Journal of Innovative Research in Technology},
year = {2026},
volume = {13},
number = {no},
pages = {688-697},
issn = {2349-6002},
url = {https://ijirt.org/article?manuscript=208799},
abstract = {Cloud Security Posture Management (CSPM) systems can produce large queues of configuration findings, yet a nominal severity label alone does not capture internet reachability, attainable privilege, asset importance, blast radius, attack-path contribution, or the regulatory relevance of the affected control. Organizations operating across India and South Korea also need a defensible way to relate one technical cloud condition to several differently structured security frameworks.
This paper presents ConfigHawk, a compliance-aware and human-gated CSPM framework with three components: a 24-control canonical AWS catalogue mapped to CERT-In, ISMS-P, ISO/IEC 27001:2022, and NIST CSF 2.0 through atomic obligations and explicit relationship types; the locked CH-SPEC-v1.0 contextual prioritization model; and a rule-first remediation workflow in which deterministic actions remain approval-gated and an LLM is restricted to optional, on-demand explanation.
The mapping dataset contains 96 reviewer-accepted mappings. In a development-set evaluation of 98 findings retained from a 100-finding AWS scan, CH-SPEC-v1.0 achieved a Spearman rank correlation of 0.885 with the provisional expert-proxy priority order, compared with 0.405 for severity-only ranking; Top-10 overlap was 9/10 versus 6/10.
These results indicate that contextual factors can improve prioritization on the studied dataset, but they are not independent validation because the expert-proxy labels and model were developed within the same research programme.},
keywords = {Cloud Security Posture Management, compliance mapping, atomic obligations, CERT-In, ISMS-P, ISO/IEC 27001, NIST CSF, risk prioritization, human-gated remediation, large language models.},
month = {September},
}
Submit your research paper and those of your network (friends, colleagues, or peers) through your IPN account, and receive 800 INR for each paper that gets published.
Join NowNational Conference on Sustainable Engineering and Management - 2024 Last Date: 15th March 2024
Submit inquiry