Quick reference for IAM policies, encryption keys, network controls, secrets, and CSPM tooling across the big three clouds.
IAMEncryptionZero TrustCompliance
Shared Responsibility
| Layer | IaaS | PaaS | SaaS |
| Data / access | You | You | You |
| App | You | You | Provider |
| OS / runtime | You | Provider | Provider |
| Hardware | Provider | Provider | Provider |
Security Service Map
| Function | AWS | Azure | GCP |
| Identity | IAM | Entra ID | Cloud IAM |
| Secrets | Secrets Mgr | Key Vault | Secret Mgr |
| Keys (KMS) | KMS | Key Vault | Cloud KMS |
| Audit log | CloudTrail | Activity Log | Audit Logs |
| Threat detect | GuardDuty | Defender | SCC |
| Guardrails | SCPs | Azure Policy | Org Policy |
IAM Commands
# AWS: short-lived creds via role
aws sts assume-role --role-arn arn:aws:iam::ACC:role/R \
--role-session-name s
aws iam attach-role-policy --role-name R --policy-arn ARN
# Azure RBAC assignment (scoped)
az role assignment create --assignee user@x.com \
--role "Storage Blob Data Reader" --scope /subscriptions/S/resourceGroups/rg
# GCP: bind role to a service account on one bucket
gcloud storage buckets add-iam-policy-binding gs://b \
--member=serviceAccount:sa@p.iam.gserviceaccount.com \
--role=roles/storage.objectViewer
Least-Privilege Policy
{ "Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:ListBucket"],
"Resource": ["arn:aws:s3:::b", "arn:aws:s3:::b/*"],
"Condition": { "Bool": { "aws:SecureTransport": "true" } }
}] }
Encryption & Secrets
# KMS key with rotation
aws kms create-key
aws kms enable-key-rotation --key-id KEY_ID
# Secret store instead of hardcoding
aws secretsmanager create-secret --name prod/db/pw \
--secret-string "$(openssl rand -base64 24)"
aws secretsmanager get-secret-value --secret-id prod/db/pw \
--query SecretString --output text
Network & Detection
# Security group: HTTPS only from internal CIDR
aws ec2 authorize-security-group-ingress --group-name web-sg \
--protocol tcp --port 443 --cidr 10.0.0.0/16
# Org-wide multi-region audit trail
aws cloudtrail create-trail --name org --s3-bucket-name logs \
--is-multi-region-trail --is-organization-trail
aws cloudtrail start-logging --name org
aws guardduty create-detector --enable
Hardening Checklist
- MFA on all humans; SSO federation, no shared logins.
- No static access keys — use roles / WIF / OIDC.
- Least privilege; deny by default; scope to resource ARNs.
- Encrypt at rest (CMK) and in transit (TLS 1.2+ enforced).
- Private subnets; no SSH/RDP from 0.0.0.0/0.
- Audit logs on, immutable, in a separate account.
- CSPM + threat detection enabled; map to CIS benchmark.
- Guardrails (SCP / Policy) prevent disabling controls.