contentintech

Cloud Security Cheatsheet

Quick reference for IAM policies, encryption keys, network controls, secrets, and CSPM tooling across the big three clouds.

IAMEncryptionZero TrustCompliance
NotesCheatsheet

Shared Responsibility

LayerIaaSPaaSSaaS
Data / accessYouYouYou
AppYouYouProvider
OS / runtimeYouProviderProvider
HardwareProviderProviderProvider

Security Service Map

FunctionAWSAzureGCP
IdentityIAMEntra IDCloud IAM
SecretsSecrets MgrKey VaultSecret Mgr
Keys (KMS)KMSKey VaultCloud KMS
Audit logCloudTrailActivity LogAudit Logs
Threat detectGuardDutyDefenderSCC
GuardrailsSCPsAzure PolicyOrg Policy

IAM Commands

# AWS: short-lived creds via role
aws sts assume-role --role-arn arn:aws:iam::ACC:role/R \
  --role-session-name s
aws iam attach-role-policy --role-name R --policy-arn ARN

# Azure RBAC assignment (scoped)
az role assignment create --assignee user@x.com \
  --role "Storage Blob Data Reader" --scope /subscriptions/S/resourceGroups/rg

# GCP: bind role to a service account on one bucket
gcloud storage buckets add-iam-policy-binding gs://b \
  --member=serviceAccount:sa@p.iam.gserviceaccount.com \
  --role=roles/storage.objectViewer

Least-Privilege Policy

{ "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["s3:GetObject", "s3:ListBucket"],
    "Resource": ["arn:aws:s3:::b", "arn:aws:s3:::b/*"],
    "Condition": { "Bool": { "aws:SecureTransport": "true" } }
  }] }

Encryption & Secrets

# KMS key with rotation
aws kms create-key
aws kms enable-key-rotation --key-id KEY_ID

# Secret store instead of hardcoding
aws secretsmanager create-secret --name prod/db/pw \
  --secret-string "$(openssl rand -base64 24)"
aws secretsmanager get-secret-value --secret-id prod/db/pw \
  --query SecretString --output text

Network & Detection

# Security group: HTTPS only from internal CIDR
aws ec2 authorize-security-group-ingress --group-name web-sg \
  --protocol tcp --port 443 --cidr 10.0.0.0/16

# Org-wide multi-region audit trail
aws cloudtrail create-trail --name org --s3-bucket-name logs \
  --is-multi-region-trail --is-organization-trail
aws cloudtrail start-logging --name org
aws guardduty create-detector --enable

Hardening Checklist

  • MFA on all humans; SSO federation, no shared logins.
  • No static access keys — use roles / WIF / OIDC.
  • Least privilege; deny by default; scope to resource ARNs.
  • Encrypt at rest (CMK) and in transit (TLS 1.2+ enforced).
  • Private subnets; no SSH/RDP from 0.0.0.0/0.
  • Audit logs on, immutable, in a separate account.
  • CSPM + threat detection enabled; map to CIS benchmark.
  • Guardrails (SCP / Policy) prevent disabling controls.

Section navigation