Skip to main content

Security Hub v1.2.0

I. Highlights

FPT Smart Cloud introduces Security Hub v1.2.0 as part of the FPT Security Platform (FSP), adding Service Activation — a controlled onboarding flow for Tenant Admins when first using Security Hub.

This release adds an activation screen that appears automatically when an organization has not yet activated Security Hub. Tenant Admins can review the platform's capabilities — including Cloud Security Posture (available in Trial) and four upcoming modules — before completing the Terms of Use acceptance and activating the service. The scroll-to-enable mechanism in the Terms of Use dialog ensures Tenant Admins read the full terms before agreeing, which is especially important because activation authorizes Security Hub to begin read-only configuration scanning on the organization's FPT Cloud account.


II. Released Features

1. Service Activation

a. Description

Service Activation provides a controlled activation flow for Security Hub. When the service has not been activated, the system displays an introduction screen in place of all menu content. Tenant Admins read and accept the Terms of Use through a dialog with scroll enforcement, then activate the service and are redirected directly to the Dashboard.

b. Features

  • Displays the Service Activation screen in place of all menu tabs when the service has not been activated for the organization
  • Introduces 5 capability cards:
    • Cloud Security Posture (Trial) — Continuously checks FPT Cloud accounts for misconfigurations, compliance benchmarks (CIS, NIST CSF, ISO 27001), and risk-scored findings
    • Kubernetes Posture (KSPM) (Coming Soon) — Agentless Kubernetes security posture and compliance mapping
    • Runtime Threat Detection (Coming Soon) — Real-time threat detection from Kubernetes and VMs via kernel-level agents
    • Application Security (Coming Soon) — Scans repositories, pipelines, images, IaC, and SBOM in the delivery workflow
    • Investigation & Response (Coming Soon) — Attack-path graph, incident investigation, and full audit trail
  • Activate Service button opens the Cloud Security Posture Management — Terms of Use dialog with full content across 7 sections (Access Method, Scope, Data Enumerated, Scanning Cadence, Data Residency, Shared Responsibility, Authorization & Disconnection)
  • Scroll-to-enable: the agreement checkbox is enabled only after the Tenant Admin scrolls to the end of the Terms of Use — cannot be bypassed
  • Helper text auto-hides after the Tenant Admin scrolls to the end of the content
  • Accept & Activate button is active only when the checkbox is checked
  • After successful activation: immediate redirect to the Dashboard screen
  • Activation state is persistent: subsequent tab access shows real content — the Service Activation screen no longer appears
  • Access control: only Tenant Admin accounts can activate; users with other roles see a permission error when accessing the URL

c. Capacity

  • Activates instantly and applies immediately to the entire organization
  • Supports deactivation at any time from Settings → Plan tab
  • Reactivation requires accepting the Terms of Use again (telemetry data is retained for 30 days after deactivation)

d. Performance

  • Service state is checked on every menu tab access (real-time gate — no caching)
  • Redirect to Dashboard occurs immediately after successful activation

III. Bug Fixes & Improvements

(No breaking changes in this release)