The security assessment will be based on Cloud Security Alliance (CSA) Security Guidance for Critical Areas of Focus in Cloud Computing and Centre for Internet Security (CIS) configuration guidelines.
The assessment includes evaluation of:
Configuration of the Management Console / Pane
Identity and Access Management including Privilege User Access Management (PUAM)
Infrastructure and Network configuration
Protection of information and data in storage solutions
Logging, monitoring and alerting
Utilization, Integration and configuration of security solutions
Development Security Operations as Code (DevSecOps)
Involvement:
The delivery requires minimal involvement of your technical staff.
Value:
An assessment outlining the current state of the security posture in the Public Cloud solution
An evaluation of asset and resource security misconfigurations
Manage the risks associated with adoption and utilization of the Public Cloud solution
Ensure policies and security controls are implemented according to requirements
Enhance and improve security across the environment
Product - Written Report Analysis Containing the Following:
A non-technical section with an Executive Summary for management and decision makers
A technical section including detailed observations and tangible recommendations to strengthen the level of security and recommendations on how hardening can be applied