Cloud Configuration Review Checklist
Reviewed: 24 August 2026 — reviewed quarterly
Quick Answer
A cloud configuration review checks your AWS, Azure, or GCP environment against CIS Benchmarks across six domains: IAM, storage, network, logging, encryption, and public endpoints. It's a manually-validated, point-in-time assessment with a signed deliverable — different from a CSPM tool, which continuously monitors configuration but doesn't validate findings or produce audit-grade evidence.
What Is a Cloud Configuration Review?
A cloud configuration review independently checks how your AWS, Azure, or GCP environment is actually set up — permissions, storage, network exposure, logging, and encryption — against a recognised hardening standard, rather than assuming the provider's defaults or your team's existing setup are secure.
We align this review with CIS Benchmarks — consensus-based configuration guides published by the Center for Internet Security, with a dedicated benchmark for each major cloud provider. Naming the methodology explicitly matters: "we reviewed your cloud config" means little without a named, checkable standard behind it.
What We Check, Domain by Domain
| Domain | What we check |
|---|---|
| IAM (Identity and Access Management) | Overly permissive roles/policies, unused credentials, lack of MFA on privileged accounts, wildcard permissions |
| Storage | Publicly accessible buckets/blobs, missing encryption at rest, overly broad bucket/object policies |
| Network | Overly permissive security groups/firewall rules, unnecessarily exposed management ports, missing network segmentation |
| Logging & monitoring | Disabled or incomplete audit logging, missing alerting on privileged actions, short log retention |
| Encryption | Data in transit not enforced (TLS), missing encryption for databases and storage, weak key management practices |
| Public endpoints | Unintentionally internet-facing services, exposed management consoles or APIs, default credentials on exposed services |
Isn't This What My CSPM Tool Already Does?
CSPM (Cloud Security Posture Management) tools like Wiz, Prisma Cloud, or Orca are genuinely useful for continuous visibility — but they answer a different question than an independent assessment does.
| CSPM subscription | Our assessment | |
|---|---|---|
| What it does | Continuously monitors configuration against benchmark rules and flags drift as it happens | A point-in-time, manually-validated review with a signed deliverable |
| Validation | Automated rule matching — every flagged item is raw output, false positives included | Every finding manually reviewed by a security engineer before it reaches you |
| Deliverable | Dashboard and alerts, no signed report | Executive summary + technical report + signed Attestation Letter |
| Scope | Cloud configuration only | Cloud configuration + external network perimeter, in one engagement |
| Best used for | Ongoing, continuous visibility between periodic assessments | The independent, audit-recognised checkpoint your auditor or insurer asks for |
Most mature security programmes run both — continuous CSPM monitoring for day-to-day drift, and a periodic independent assessment for the audit-grade checkpoint.
Quick Self-Check Before You Order
Not sure about any of these? Our €899 External Infrastructure & Cloud Security Assessment covers exactly these domains, aligned with CIS Benchmarks and NIST SP 800-115, with one free retest included. See also internal vs external testing to confirm this is the right scope for you.
See Infrastructure & Cloud Assessment