Cloud security is shared: the provider secures parts of its service, but your organization still has to configure the customer-controlled protections for its accounts, data, workloads and response process. Start by mapping those responsibilities for each service, then prioritize identity and access, audit logging, data protection, network exposure and incident readiness.
Start with a checklist for each cloud service
Do not assume that a provider’s secure infrastructure means your organization’s accounts and workloads are securely configured. Responsibility changes with the service model, the specific service, the workload and applicable requirements. Microsoft’s shared responsibility guidance, updated August 24, 2026, describes how customer and provider duties vary across cloud service models. AWS likewise explains customer-specific duties in its IAM and STS security guidance.
For every workload or SaaS product, record its service model and confirm responsibility for each control using the provider’s current, service-specific documentation. Do not treat an IaaS, PaaS or SaaS label as a complete responsibility map.
| Control area | What to record for each service |
|---|---|
| Identity and access | Who configures users, administrators, roles, service identities and access reviews? |
| Data and encryption | Who classifies the data, selects protection settings, and governs encryption and keys? |
| Network access | Who controls network rules, service endpoints and public exposure? |
| Operating systems and applications | Who maintains the operating system, platform components and application configuration? |
| Backups and recovery | Who configures backups and is responsible for restoring the service or data? |
| Logging and monitoring | Who enables, retains and reviews activity records, and who responds to alerts? |
Write down the named owner for each control, including where responsibility is shared. If the provider documentation is unclear for a particular service, resolve that uncertainty before treating the control as covered.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Secure identities before tuning less urgent settings
Accounts are a high-impact place to begin. CISA says, “Strong passwords help, but they are no longer enough to keep accounts and systems safe when used alone.” Its MFA guidance recommends multifactor authentication and discusses phishing-resistant options.
- Require MFA wherever it is supported. Start with administrators and other privileged accounts, then cover all users and access paths the service makes available.
- Prefer phishing-resistant MFA when supported. A compatible security key is one option; check that its protocol works with your identity provider and the cloud services you use before purchasing. A key strengthens authentication but does not replace the rest of this checklist.
- Review both people and service identities. Remove accounts and credentials that are no longer needed, and confirm that non-human identities have an owner and a defined purpose.
- Grant only necessary permissions. Use roles that match job duties and workload needs, and review privileged grants instead of relying on broad access by default.
- Check provider-specific defaults. Google Cloud’s secure enterprise foundation controls call attention to automatic broad role grants for default service accounts. Check the relevant provider and service guidance rather than assuming all defaults behave alike.
Make cloud logs actionable and difficult to tamper with
Logging is useful only if the right events are collected, protected and acted on. CISA’s business-system logging guidance covers enabling logs, centralizing them, restricting access, setting retention and assigning incident responsibilities.
Rank #2
- Enable audit and activity logging for the cloud services and accounts that support it. Check coverage for administrative actions and the workloads that matter to your organization.
- Centralize records so responders can investigate across services rather than depending on isolated local views.
- Restrict who can read, change or delete logs. Separate log administration from ordinary workload administration where your service supports it.
- Set retention deliberately. Choose a period that supports your response process and applicable compliance needs; the appropriate duration depends on those requirements and is not universal.
- Alert on high-risk events. At minimum, consider failed logins and privilege changes where the provider exposes those events and alerting controls.
- Name the reviewer and responder. Specify who receives alerts, who assesses them, and how an incident is escalated. An alert without an owner is not a complete monitoring control.
Protect data and secrets according to their use
Classify the information handled by each workload before deciding what protections it needs. Microsoft’s shared-responsibility guidance places data and encryption decisions among customer responsibilities; AWS’s security design principles call for protecting data in transit and at rest.
- Identify the data types and the requirements that apply to them.
- Decide how data should be protected in transit and at rest, then confirm which settings the specific provider service exposes and who must configure them.
- Set governance for encryption choices and keys. Do not assume the provider has made every customer decision for you.
- Manage secrets deliberately: identify where applications depend on them, limit access to the people or workloads that need them, and assign an owner for their handling.
A generic cloud checklist cannot prescribe one encryption or key configuration for every workload. Use the service documentation and your organization’s data requirements to determine the appropriate choices.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteReview infrastructure and network exposure
Use a provider-specific organization and infrastructure baseline, then examine the paths into each workload. Google Cloud’s secure-foundation controls cover organization and networking, while its minimum viable secure platform guidance describes a baseline that can progress through basic, intermediate and advanced controls according to use case.
- Inspect network rules and identify resources exposed to the public internet.
- Where narrower rules meet the workload’s needs, avoid broad access.
- Review organization-level and infrastructure controls against the selected provider’s current baseline.
- Record why external access is needed and who is responsible for reviewing it.
Providers expose different controls and defaults. Do not copy a setting or console path from one service to another without confirming that it applies to the service you actually use.
Rank #4
Connect detection to recovery and incident response
Logging and metrics should feed a response process, not sit unused. AWS Well-Architected’s security design principles, in its March 31, 2022 dated version, include preparing for security events and using collected telemetry to investigate and act.
- Assign incident roles, including who can make decisions and who handles technical investigation.
- Document how responders access relevant logs and metrics and how they investigate suspicious activity.
- Define escalation and communication steps for a suspected incident.
- Establish how affected services or data will be recovered, using the backup and recovery responsibilities recorded for each service.
Use SaaS assessment tools where they fit
For SaaS environments, CISA lists its Secure Cloud Business Applications (SCuBA) resources as no-cost assessment and hardening tools. The listed controls include MFA, strong passwords and audit logging. Confirm that a tool applies to your specific SaaS product and covers the controls you need before relying on it; the listing does not establish identical coverage for every SaaS service.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Turn the checklist into a recurring review
Use the checklist as a baseline, not a one-time certification. Google Cloud recommends progressing from basic to intermediate and advanced controls according to the use case; its guidance does not mean every organization needs the same maturity level.
Quick Recap
- Revisit access grants and privileged roles.
- Check whether logging, alert ownership and retention still match the services in use.
- Review public exposure and network rules after infrastructure or workload changes.
- Confirm data protections, service ownership and incident contacts remain accurate.
- Check updated provider recommendations when services or configurations change.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

