🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · Cloud Security

Cloud Configuration Review Checklist

Reviewed: 24 August 2026 — reviewed quarterly

Quick Answer

A cloud configuration review checks your AWS, Azure, or GCP environment against CIS Benchmarks across six domains: IAM, storage, network, logging, encryption, and public endpoints. It's a manually-validated, point-in-time assessment with a signed deliverable — different from a CSPM tool, which continuously monitors configuration but doesn't validate findings or produce audit-grade evidence.

What Is a Cloud Configuration Review?

A cloud configuration review independently checks how your AWS, Azure, or GCP environment is actually set up — permissions, storage, network exposure, logging, and encryption — against a recognised hardening standard, rather than assuming the provider's defaults or your team's existing setup are secure.

We align this review with CIS Benchmarks — consensus-based configuration guides published by the Center for Internet Security, with a dedicated benchmark for each major cloud provider. Naming the methodology explicitly matters: "we reviewed your cloud config" means little without a named, checkable standard behind it.

What We Check, Domain by Domain

DomainWhat we check
IAM (Identity and Access Management)Overly permissive roles/policies, unused credentials, lack of MFA on privileged accounts, wildcard permissions
StoragePublicly accessible buckets/blobs, missing encryption at rest, overly broad bucket/object policies
NetworkOverly permissive security groups/firewall rules, unnecessarily exposed management ports, missing network segmentation
Logging & monitoringDisabled or incomplete audit logging, missing alerting on privileged actions, short log retention
EncryptionData in transit not enforced (TLS), missing encryption for databases and storage, weak key management practices
Public endpointsUnintentionally internet-facing services, exposed management consoles or APIs, default credentials on exposed services

Isn't This What My CSPM Tool Already Does?

CSPM (Cloud Security Posture Management) tools like Wiz, Prisma Cloud, or Orca are genuinely useful for continuous visibility — but they answer a different question than an independent assessment does.

CSPM subscriptionOur assessment
What it doesContinuously monitors configuration against benchmark rules and flags drift as it happensA point-in-time, manually-validated review with a signed deliverable
ValidationAutomated rule matching — every flagged item is raw output, false positives includedEvery finding manually reviewed by a security engineer before it reaches you
DeliverableDashboard and alerts, no signed reportExecutive summary + technical report + signed Attestation Letter
ScopeCloud configuration onlyCloud configuration + external network perimeter, in one engagement
Best used forOngoing, continuous visibility between periodic assessmentsThe independent, audit-recognised checkpoint your auditor or insurer asks for

Most mature security programmes run both — continuous CSPM monitoring for day-to-day drift, and a periodic independent assessment for the audit-grade checkpoint.

Quick Self-Check Before You Order

Do you know which IAM roles have administrative or wildcard permissions?
Are any storage buckets/blobs publicly accessible, even unintentionally?
Are security groups/firewall rules reviewed, or just accumulated over time?
Is audit logging enabled and retained long enough to investigate an incident?
Is data encrypted at rest and in transit consistently, not just where convenient?
Do you know every management console or API that's reachable from the public internet?

Not sure about any of these? Our €899 External Infrastructure & Cloud Security Assessment covers exactly these domains, aligned with CIS Benchmarks and NIST SP 800-115, with one free retest included. See also internal vs external testing to confirm this is the right scope for you.

See Infrastructure & Cloud Assessment

Frequently Asked Questions

What is a CIS Benchmark?+
CIS Benchmarks are consensus-based configuration hardening guides published by the Center for Internet Security, with a dedicated benchmark for each major cloud provider (AWS, Azure, GCP) and many of their individual services. They translate broad security principles into specific, checkable configuration settings — which IAM policies to avoid, which storage settings to require, which network exposures to close.
Do you check every CIS Benchmark control?+
We focus the review on the domains most relevant to real-world misconfiguration risk — IAM, storage, network, logging, encryption, and public endpoints — rather than mechanically ticking every control in a multi-hundred-item benchmark document, many of which are organisational/process controls rather than technical settings we can independently verify.
Why do I need this if I already use a CSPM tool like Wiz, Prisma Cloud, or Orca?+
CSPM tools are excellent for continuous, automated visibility between periodic checks — they run constantly and flag drift as it happens. What they don't do is validate findings manually, cover your external network perimeter (they're cloud-only), or produce a signed, auditor-recognised deliverable. Think of a CSPM subscription as continuous monitoring and our assessment as the independent, manually-validated checkpoint most compliance programmes still need alongside it — not instead of it.
Can this replace a web application penetration test?+
No. This checklist and our underlying assessment cover your cloud environment's configuration and external network perimeter, not your application code or API surface. For that, see our web-application Penetration Testing tiers (from €539).
Which compliance frameworks does this map to?+
ISO 27001 Annex A.8.20 (network security), GDPR Article 32 (security of processing), and NIS2 Article 21 (cybersecurity risk-management measures) all expect evidence that network and cloud configuration have been independently assessed — this checklist reflects the domains our External Infrastructure & Cloud Security Assessment covers for that evidence.
Do you cover multi-cloud environments?+
One cloud environment (AWS, Azure, or GCP) is included in our standard €899 assessment. Multi-cloud environments are quoted on request — contact us with your architecture and we'll scope it.