contentintech
Learn/cloud/Cloud Security
Advanced~20 min read

Cloud Security

Shared responsibility, IAM, encryption, network isolation, secrets management, and posture management across AWS, Azure, and GCP.

IAMEncryptionZero TrustCompliance

The Shared Responsibility Model

Cloud security is a partnership. The provider secures the cloud itself — physical data centres, the hypervisor, and the managed service control plane. You secure what you put in the cloud — your data, identities, configuration, and network rules. The dividing line shifts by service model: with IaaS you patch the OS; with SaaS the provider does. Most breaches happen on the customer side, and the leading cause is misconfiguration, not a broken provider.

LayerIaaSPaaSSaaS
Data & accessYouYouYou
ApplicationYouYouProvider
OS / runtimeYouProviderProvider
Hypervisor / hardwareProviderProviderProvider

Identity & Access Management

IAM is the new perimeter. The governing principle is least privilege: grant the minimum permissions needed, prefer temporary role assumption over long-lived keys, and never attach admin policies to day-to-day identities. Human users authenticate through SSO with MFA; workloads authenticate through roles and workload identity federation — no secrets stored on disk.

A least-privilege policy

json
# AWS IAM policy: read-only on ONE bucket, nothing else
{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "ReadReportsOnly",
    "Effect": "Allow",
    "Action": ["s3:GetObject", "s3:ListBucket"],
    "Resource": [
      "arn:aws:s3:::acme-reports",
      "arn:aws:s3:::acme-reports/*"
    ],
    "Condition": { "Bool": { "aws:SecureTransport": "true" } }
  }]
}
bash
# Assume a role for short-lived credentials instead of static keys
aws sts assume-role --role-arn arn:aws:iam::111122223333:role/ReportReader \
  --role-session-name analytics-job

# Azure RBAC role assignment scoped to one resource group
az role assignment create --assignee user@acme.com \
  --role "Storage Blob Data Reader" \
  --scope /subscriptions/SUB/resourceGroups/reports-rg

# GCP: grant a role on a single bucket, not the project
gcloud storage buckets add-iam-policy-binding gs://acme-reports \
  --member=serviceAccount:job@acme.iam.gserviceaccount.com \
  --role=roles/storage.objectViewer
ConceptAWSAzureGCP
Identity serviceIAMEntra IDCloud IAM
Workload identityIAM RolesManaged IdentitiesService Accounts / WIF
Secrets storeSecrets ManagerKey VaultSecret Manager
Key managementKMSKey Vault KeysCloud KMS
Posture mgmtSecurity HubDefender for CloudSecurity Command Center

Kill long-lived keys

Static access keys are the number-one credential found in leaked repos. Use OIDC federation for CI/CD (GitHub Actions to AWS/GCP without secrets), managed identities for VMs, and short-lived STS tokens for humans. If a static key must exist, rotate it on a schedule and alert on use outside expected regions.

Encryption & Key Management

Encrypt at rest and in transit everywhere. At rest, provider-managed keys are the floor; customer-managed keys (CMK) in a KMS give you rotation, audit trails, and the ability to revoke access by disabling the key. In transit, enforce TLS 1.2+ and reject plaintext at the policy layer.

bash
# Create a customer-managed key with automatic annual rotation (AWS KMS)
aws kms create-key --description "acme-app data key"
aws kms enable-key-rotation --key-id KEY_ID

# Store and retrieve an app secret instead of hardcoding it
aws secretsmanager create-secret --name prod/db/password \
  --secret-string "$(openssl rand -base64 24)"
aws secretsmanager get-secret-value --secret-id prod/db/password \
  --query SecretString --output text

Network Isolation & Zero Trust

Segment workloads into private subnets inside a VPC/VNet. Security groups and NSGs are stateful, instance-level firewalls — default-deny inbound and open only the ports you need. Zero Trust extends this: never trust based on network location alone; authenticate and authorize every request, and prefer private endpoints over public IPs.

bash
# Security group that allows HTTPS only, from a specific CIDR
aws ec2 create-security-group --group-name web-sg --description "web tier" --vpc-id vpc-abc
aws ec2 authorize-security-group-ingress --group-name web-sg \
  --protocol tcp --port 443 --cidr 10.0.0.0/16
# (No SSH from 0.0.0.0/0 — use Session Manager / bastion instead)

# GCP firewall: deny-by-default, allow internal HTTPS
gcloud compute firewall-rules create allow-internal-https \
  --network=acme-vpc --direction=INGRESS --action=ALLOW \
  --rules=tcp:443 --source-ranges=10.128.0.0/9

Detection, Logging & Posture Management

You cannot secure what you cannot see. Turn on the audit log (CloudTrail, Azure Activity Log, Cloud Audit Logs) in every account and region, ship it to an immutable, separate account, and layer threat detection on top (GuardDuty, Defender, SCC). CSPM tools continuously scan for misconfigurations — public buckets, unencrypted volumes, over-broad IAM — and map findings to benchmarks like the CIS Foundations.

bash
# Enable an org-wide, multi-region audit trail
aws cloudtrail create-trail --name org-trail --s3-bucket-name acme-audit-logs \
  --is-multi-region-trail --is-organization-trail
aws cloudtrail start-logging --name org-trail

# Turn on threat detection
aws guardduty create-detector --enable

Defense in depth

No single control is enough. A public bucket protected by a bucket policy, KMS encryption, versioning with Object Lock, VPC endpoints, and a CSPM alert survives the failure of any one layer. Assume every individual control will eventually be misconfigured and design so that the next layer catches it.

Compliance & Governance

Frameworks such as SOC 2, ISO 27001, PCI-DSS, HIPAA, and GDPR translate into concrete cloud controls: encryption, access logging, data residency, and separation of duties. Enforce guardrails with organization policies (SCPs, Azure Policy, GCP Org Policy) so that even an admin cannot, for example, disable encryption or create a public bucket.

json
# AWS Service Control Policy: block disabling of CloudTrail org-wide
{ "Version": "2012-10-17",
  "Statement": [{ "Effect": "Deny",
    "Action": ["cloudtrail:StopLogging", "cloudtrail:DeleteTrail"],
    "Resource": "*" }] }

Practice Exercises

  1. Write an IAM policy that lets a service read from one bucket and write to a second, denies everything else, and requires TLS. Attach it to a role and assume that role for short-lived credentials.
  2. Configure OIDC federation so a GitHub Actions workflow can deploy to your cloud without any stored static credentials. Explain why this is safer than a stored key.
  3. Create a customer-managed KMS key with rotation enabled, use it to encrypt a volume or bucket, then disable the key and observe that access is revoked.
  4. Build a VPC with a public and a private subnet, place a database in the private subnet, and prove it has no route to the internet while the app tier does.
  5. Enable an organization-wide, multi-region audit trail delivered to a separate logging account, and add an SCP that prevents anyone from stopping it.
  6. Run a CSPM scan (Security Hub / Defender / SCC), pick three high-severity findings, and remediate them. Map each finding to a CIS benchmark control.

Section navigation