Cloud Security
Cloud Security Shared Responsibility Checklist (AWS, Azure, GCP)
A CSP-agnostic checklist for tenant IAM, logging, encryption, network, and well-architected security pillars.
- Estimated time
- 4–12 Weeks
- Audience
- Cloud Architects, Security, and Platform Teams
- Last updated
Operational reference for cloud-tenant security. Provider certifications do not transfer customer-configured risk.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Accounts & Identity
Phase 2: Logging & Detection
Phase 3: Data & Network
Phase 4: Build & Govern
FAQ
Does the CSP’s SOC 2 cover us?+–
It covers the provider’s controls. You still own tenant configuration (the shared-responsibility model).
AWS vs Azure vs GCP?+–
Controls differ by name; the themes (identity, logging, encryption, network, CI) are the same.
What is a SCP?+–
In AWS, Service Control Policies constrain accounts in an Organization. Azure/GCP have analogous guardrails.
Is WAF enough?+–
It is one layer. App authorization bugs still need ASVS-style testing.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer