Quick Testing: Cloud Security Assessment

Review of cloud configuration, identity management, and exposure risks

 
01

Assessment covers security-relevant cloud constructs and exposures

  • Cloud accounts/subscriptions and their structure
  • Identity and access management (users, roles, service principals)
  • Public exposure points (services, storage, endpoints)
  • Network configuration and connectivity (VPC/VNet, peering, gateways)
 
02

How cloud configurations behave under realistic threat scenarios

  • Review of IAM policies for excessive privileges and trust misconfigurations
  • Identification of unintended public access and data exposure paths
  • Evaluation of network controls and segmentation effectiveness
  • Simulation of privilege escalation and cross-service access paths
  • Mapping to MITRE ATT&CK cloud techniques for adversarial context

Guided by provider best practices (e.g., AWS Well-Architected, Azure Security Benchmark) and NIST SP 800-53 where applicable.

 
03

Focus on misconfigurations with real security implications

  • Over-permissive identities and role assumptions
  • Publicly exposed or weakly protected resources
  • Chained access paths enabling privilege escalation or lateral movement
  • Gaps in visibility, logging, or control enforcement

All findings are supported with clear evidence and practical impact description.

 
04

Provides input towards alignment

  • ISO/IEC 27001 cloud security and access control domains
  • NIST CSF and NIST SP 800-53 cloud-relevant controls
  • CIS Benchmarks for AWS, Azure, and GCP configuration baselines
  • DORA and NIS2 regulatory frameworks for cloud risk management