Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Audit cloud security by defining exactly which accounts, projects, subscriptions, workloads, and data are in scope; measuring them against a versioned, relevant baseline; recording evidence and exceptions; and verifying fixes with a fresh assessment. The process is repeatable, but the controls must fit the cloud provider, services, workload design, and requirements being audited.

What a cloud security configuration audit should establish

A useful audit shows whether the configurations of the in-scope cloud resources match an agreed security baseline, where they do not, and what is being done about the gaps. It should also make its conclusions traceable: another reviewer should be able to identify the resources checked, the requirement applied, the evidence observed, and the time of assessment.

An audit is not the same as proof that a provider’s infrastructure is secure or that an organization meets every legal or contractual obligation. Cloud security follows a shared-responsibility model: provider and customer duties vary by service, and customer responsibilities are also shaped by the data, requirements, and applicable laws. AWS summarizes this as “Security is a shared responsibility between AWS and you.” Establish the customer-side controls in scope rather than treating a provider’s assurance as evidence that customer configuration is safe.

How to plan and run the audit

1. Define the boundary and purpose

Write down why the audit is being performed—for example, an internal risk review, a change review, or preparation for a specified compliance assessment. Then establish the boundary. Identify the cloud tenants, organizations, accounts, subscriptions, projects, regions, workloads, and resource types to examine. Include systems that store, transmit, or process sensitive data, and note the relevant jurisdictions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For each service in scope, determine which security controls are the customer’s responsibility and who owns them. An audit of a particular account or set of workloads should not be described as covering the whole organization unless the inventory and evidence support that claim.

2. Select and tailor a versioned baseline

Choose a provider-native recommendation, a service-specific benchmark, or a recognized checklist that fits the resources and risk posture in scope. Record its name, edition or version, publication or retrieval date, applicable services, and any tailoring. For every tailored or excluded control, capture the reason so that the boundary of the assessment remains clear.

NIST SP 800-70 Rev. 5 describes security configuration checklists as a way to configure and verify systems, identify unauthorized changes, and produce artifacts about security posture. Its guidance notes that checklists can help minimize attack surface and identify changes that might otherwise go undetected. A checklist is a measuring tool, not a substitute for deciding whether each requirement fits the actual workload.

Baselines are not interchangeable. Google Cloud organizes its recommended minimum platform guidance into Basic, Intermediate, and Advanced levels and recommends applying it progressively according to use cases. Its guidance covers authentication and authorization, organization, infrastructure, data protection, network security, and monitoring, logging, and alerting. Google Cloud said in a 2026 announcement that its checklist contains 60 controls vetted by its Office of the CISO and subject-matter experts; treat that figure as describing that checklist, not as a universal minimum for every cloud audit. For Azure, CIS publishes separate benchmarks for Compute Services, Database Services, Foundations, and Storage Services; select the relevant benchmark and confirm its listed version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Examine the controls that matter to the scope

Use the selected baseline to assess actual services and configurations. Avoid applying a setting mechanically when the requirement depends on a workload, data classification, or documented exception.

  • Identity and privileged access: Review administrative identities, authentication strength, access assignments and approvals, privileged access governance, emergency accounts, and administrative access paths. Microsoft’s cloud security benchmark calls for a documented identity and privileged-access strategy, strong authentication, and periodic governance of exceptions.
  • Organization and governance: Check account, project, and subscription structure; security ownership; separation of duties; and whether organizational policies and guardrails apply to the resources in scope. Organization management is also one of Google Cloud’s recommended checklist domains.
  • Network security: Examine segmentation, ingress and egress, internet exposure, hybrid connections, network monitoring, and whether current network diagrams or architecture artifacts reflect the environment. Microsoft’s benchmark includes network segmentation and a network security strategy.
  • Data protection: Identify sensitive-data locations and flows. Compare access restrictions, encryption, and key lifecycle controls with the selected baseline and business requirements. Microsoft recommends tracking and minimizing the sensitive-data footprint and controlling data and access keys through their lifecycle.
  • Logging, monitoring, and response: Determine whether relevant control-plane and resource logs are collected, retained for the intended scenarios, reviewed or used for alerts, and available to response teams. Google includes monitoring, logging, and alerting in its checklist domains; Microsoft recommends aligning log capture and retention with threat detection, incident response, and compliance scenarios.
  • Configuration and vulnerability management: Compare resource settings with defined baselines, look for configuration drift and unsupported or vulnerable components, and check whether findings are assigned and remediated. Microsoft recommends baselines for different resource types and ongoing measurement, audit, enforcement, and review.
  • Other workload-dependent controls: Include backup and recovery, endpoint security, and DevOps controls when the in-scope systems depend on them. Microsoft’s benchmark includes backup protection and monitoring and recommends security controls throughout the DevOps lifecycle.

4. Record evidence and exceptions

Make each result reproducible. Keep a record for every assessed control, including:

  • Resource identifier and its account, project, subscription, and region.
  • Baseline requirement, including its name and version.
  • Expected state and observed configuration.
  • Collection method and observation time, with a reference to the evidence location.
  • Result: pass, fail, not applicable, or not assessed.
  • Risk and likely business effect, remediation owner, and target date.
  • For an exception: rationale, approver, compensating controls, and review or expiry date.

Protect raw exports, screenshots, and reports as security-sensitive information. NIST’s checklist guidance supports the underlying purpose of this recordkeeping: verifying configuration, detecting unauthorized change, and producing posture artifacts.

5. Use assessment tools without mistaking findings for a verdict

Automated assessment can make repeated checks easier, but the result is only as useful as its coverage, configuration, and evidence. Confirm the cloud and resource types supported, control-framework mappings and versions, account and region coverage, permissions and recording prerequisites, evidence export, exception handling, and remediation tracking.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • AWS Security Hub CSPM: AWS describes it as a service for assessing an AWS environment against standards and best practices, with continuous account-level configuration and security checks. Most controls require AWS Config to be enabled and recording resources. Confirm that prerequisite and the account and region coverage before relying on the findings.
  • Prowler: AWS Prescriptive Guidance describes Prowler as an open-source command-line tool for assessing, auditing, and monitoring AWS accounts against best practices and security frameworks. Verify the frameworks and resources relevant to the assessment rather than assuming a scan covers every requirement.
  • Microsoft Defender for Cloud CSPM: Microsoft describes security posture visibility and assessment across Azure, AWS, and Google Cloud against standards selected for those environments. Check the selected standards and actual environment coverage against the audit boundary.

A tool’s pass result does not establish that every relevant control was assessed, that every resource was included, or that the organization satisfies an audit or legal requirement. Preserve the tool’s scope and prerequisites alongside its output.

6. Prioritize, remediate, and reassess

Prioritize findings using exposure, business criticality, data sensitivity, threat context, and the purpose of the chosen baseline. Assign an accountable owner and due date to each fix. If a risk is accepted, record the approver, rationale, compensating controls, and a review or expiry date instead of treating the exception as a permanent pass.

After remediation, collect fresh evidence and record the verification result. Schedule reassessments and monitor for configuration changes between formal audits. Microsoft recommends continuous measurement and regular posture reviews; Google recommends using monitoring tools to audit continued compliance after implementing its baseline.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose an audit baseline or tool

Compare options against the environment and the evidence the audit needs, rather than selecting one solely because it is familiar or automated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Coverage: Does it include the provider, regions, accounts, and actual resource types in scope?
  • Guidance type: Is it provider-native, service-specific, or cross-cloud, and does that match the audit objective?
  • Mapping and version: Which framework or benchmark is used, and which edition or version?
  • Assessment cadence: Is it a one-time snapshot, scheduled check, or continuous monitoring?
  • Evidence and workflow: Can you retain or export results, preserve an audit trail, document exceptions, and track remediation?
  • Operational prerequisites: What permissions, configuration, resource recording, and account or region setup are needed?
  • Organizational fit: Does the approach reflect workload design, organizational risk, and applicable legal or contractual requirements?

What to do with the audit results

Keep the final record tied to the scope and baseline that produced it. It should distinguish failed controls from items not assessed or not applicable, explain exceptions, identify owners and target dates, and show whether fixes were verified. Use that record to direct remediation and future monitoring; do not turn an incomplete scan or a single snapshot into a broader assurance claim.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.