Skip to content

Runbook 02 — Enterprise AWS Cloud Security Assessment

Item Value
Module Module 02 — AWS Cloud Penetration Testing
Runbook 02 — Enterprise AWS Cloud Security Assessment
Audience Cloud Security Engineers, Cloud Security Consultants, Red Teams, Blue Teams, Cloud Architects
Assessment Type Enterprise Cloud Security Assessment
Estimated Duration 3–10 Days
Frameworks AWS Well-Architected Framework, CIS AWS Foundations Benchmark, NIST CSF, MITRE ATT&CK, ISO 27001, PCI DSS

This runbook provides a structured methodology for performing a complete enterprise AWS Cloud Security Assessment.

Unlike a penetration test, this assessment evaluates the overall security posture of the AWS environment by reviewing architecture, governance, configurations, identity, monitoring and operational security controls.

The assessment helps organizations answer:

  • Is our AWS environment secure?
  • What are our highest risks?
  • Are security controls implemented correctly?
  • Are we compliant with industry standards?
  • How can we improve our cloud security posture?

CloudNova Technologies has been engaged by FinSecure Bank Ltd to conduct an enterprise-wide AWS Cloud Security Assessment across multiple AWS accounts before a regulatory audit.

The environment includes:

  • AWS Organizations
  • 24 AWS Accounts
  • Amazon EC2
  • Amazon EKS
  • AWS Lambda
  • Amazon S3
  • Amazon RDS
  • AWS IAM Identity Center
  • Security Hub
  • GuardDuty
  • AWS Config
  • Security Lake
  • Hybrid VPN Connectivity

Management requires a comprehensive security review and a prioritized remediation roadmap.


Engagement Planning
Architecture Review
Identity Assessment
Network Security Assessment
Compute Security Assessment
Storage Security Assessment
Container Security Assessment
Serverless Security Assessment
Monitoring Assessment
Governance Assessment
Compliance Assessment
Risk Analysis
Reporting
Executive Presentation

Understand the enterprise environment before beginning the assessment.

  • Review project scope
  • Confirm AWS accounts
  • Identify AWS Regions
  • Identify critical business applications
  • Review architecture diagrams
  • Confirm compliance requirements
  • Review previous assessments

  • Assessment Scope
  • Project Plan
  • Asset List
  • Rules of Engagement

Review:

  • AWS Organizations
  • Organizational Units (OUs)
  • Management Account
  • Member Accounts
  • Delegated Administrators
  • Service Control Policies (SCPs)
  • Account Separation

Questions

  • Are production workloads isolated?
  • Are SCPs implemented?
  • Are development accounts separated?

  • AWS Organization Security Review

Phase 3 — Identity & Access Management Assessment

Section titled “Phase 3 — Identity & Access Management Assessment”

Review:

  • IAM Users
  • IAM Roles
  • IAM Groups
  • IAM Policies
  • Identity Center
  • MFA
  • Access Keys
  • Trust Relationships
  • Cross-Account Roles

Assess:

  • Least privilege
  • Administrator roles
  • Privilege escalation
  • Identity governance

  • IAM Security Assessment

Review:

  • Amazon VPC
  • Public Subnets
  • Private Subnets
  • Route Tables
  • Internet Gateways
  • NAT Gateways
  • Security Groups
  • Network ACLs
  • VPC Peering
  • Transit Gateway
  • PrivateLink
  • DNS

Assess:

  • Internet exposure
  • Network segmentation
  • Zero Trust implementation
  • East-west traffic

  • Network Security Assessment

Review:

  • Amazon EC2
  • Auto Scaling
  • Launch Templates
  • IMDS
  • User Data
  • EBS Encryption
  • Instance Profiles
  • Patch Management
  • Systems Manager

Assess:

  • Public instances
  • Administrative access
  • Operating system hardening
  • Compute governance

  • EC2 Security Assessment

Review:

  • Amazon S3
  • Amazon EBS
  • Amazon EFS
  • Amazon FSx
  • AWS Backup

Assess:

  • Encryption
  • Public access
  • Versioning
  • Backup security
  • Cross-account access
  • Lifecycle policies

  • Storage Security Assessment

Review:

  • Amazon RDS
  • Aurora
  • DynamoDB
  • Redshift
  • ElastiCache

Assess:

  • Encryption
  • Authentication
  • IAM integration
  • Public accessibility
  • Backup configuration
  • Logging

  • Database Security Assessment

Phase 8 — Kubernetes Security Assessment

Section titled “Phase 8 — Kubernetes Security Assessment”

Review:

  • Amazon EKS
  • RBAC
  • Service Accounts
  • IRSA
  • Secrets
  • ConfigMaps
  • Network Policies
  • Admission Controllers
  • Worker Nodes
  • Container Images

Assess:

  • Cluster hardening
  • Privileged workloads
  • Pod Security
  • Runtime security

  • Kubernetes Security Assessment

Phase 9 — Serverless Security Assessment

Section titled “Phase 9 — Serverless Security Assessment”

Review:

  • Lambda Functions
  • Execution Roles
  • Layers
  • Event Sources
  • Environment Variables
  • Function URLs
  • API Gateway

Assess:

  • IAM permissions
  • Secrets management
  • Runtime security
  • Dependency management

  • Serverless Security Assessment

Phase 10 — Logging & Monitoring Assessment

Section titled “Phase 10 — Logging & Monitoring Assessment”

Review:

  • CloudTrail
  • CloudWatch
  • AWS Config
  • GuardDuty
  • Security Hub
  • Detective
  • Security Lake
  • VPC Flow Logs
  • EKS Audit Logs

Assess:

  • Detection capability
  • Log retention
  • Alerting
  • SOC visibility

  • Logging & Monitoring Assessment

Review:

  • AWS Config Rules
  • Security Hub Standards
  • Tagging Strategy
  • SCPs
  • Backup Policies
  • Change Management
  • Patch Management

Assess:

  • Governance maturity
  • Policy enforcement
  • Operational consistency

  • Cloud Governance Assessment

Evaluate compliance against:

  • CIS AWS Foundations Benchmark
  • AWS Well-Architected Security Pillar
  • ISO 27001
  • PCI DSS
  • NIST Cybersecurity Framework

Assess:

  • Control implementation
  • Evidence availability
  • Compliance gaps

  • Compliance Gap Assessment

Identify:

  • Public EC2
  • Public Load Balancers
  • Public APIs
  • Public S3 Buckets
  • Public Lambda URLs
  • Public Databases
  • Exposed Kubernetes Services

Document:

  • Internet-facing assets
  • Business criticality
  • Risk level

  • Internet Attack Surface Report

Classify findings.

Severity Description
Critical Immediate business impact
High Significant enterprise risk
Medium Moderate security weakness
Low Minor issue
Informational Best practice recommendation

Prioritize based on:

  • Likelihood
  • Technical Impact
  • Business Impact
  • Regulatory Impact

  • Enterprise Risk Register

Metric Example
AWS Accounts Reviewed 24
Critical Findings 8
High Findings 19
Medium Findings 34
Low Findings 17
IAM Roles Reviewed 520
EC2 Instances 740
S3 Buckets 315
EKS Clusters 18
Lambda Functions 410
Public Assets 82

The assessment report should contain:

Business overview of the assessment.


  • AWS Accounts
  • Regions
  • Services
  • Applications

Assessment standards followed.


For each finding include:

  • Description
  • Evidence
  • Business Impact
  • Risk Rating
  • Remediation

Security architecture observations.


Control mapping and compliance gaps.


Immediate (0–30 Days)

  • Enable MFA for privileged identities.
  • Remove public access from sensitive resources.
  • Restrict IAM permissions.
  • Enable organization-wide CloudTrail.

Short-Term (30–90 Days)

  • Harden EKS clusters.
  • Implement least privilege.
  • Improve monitoring.
  • Enable Security Hub standards.

Long-Term (90–180 Days)

  • Adopt Zero Trust Architecture.
  • Implement continuous CSPM.
  • Perform quarterly cloud security reviews.
  • Automate compliance validation.

Assessment Area Status
AWS Organizations
IAM
Networking
EC2
Storage
Databases
Amazon EKS
Lambda
Logging
Monitoring
Governance
Compliance
Attack Surface
Risk Register
Executive Report

At the end of the assessment, provide:

  • Executive Summary
  • Scope Document
  • AWS Organization Review
  • IAM Security Assessment
  • Network Security Assessment
  • Compute Security Assessment
  • Storage Security Assessment
  • Database Security Assessment
  • Kubernetes Security Assessment
  • Serverless Security Assessment
  • Logging & Monitoring Assessment
  • Governance Assessment
  • Compliance Assessment
  • Internet Attack Surface Report
  • Enterprise Risk Register
  • Executive Dashboard
  • Final Cloud Security Assessment Report
  • Executive Presentation
  • Prioritized Remediation Roadmap

The assessment is considered successful when:

  • All in-scope AWS accounts and services have been reviewed.
  • Security posture has been evaluated across identity, networking, compute, storage, Kubernetes and serverless workloads.
  • Compliance gaps have been identified and documented.
  • Business risks have been prioritized.
  • Executive stakeholders receive a clear security maturity assessment and actionable remediation roadmap.

  • Enterprise cloud security assessments provide a holistic view of an organization’s AWS security posture beyond penetration testing alone.
  • Identity, governance, networking, workloads, monitoring and compliance should be assessed together to understand overall risk.
  • Continuous assessments help detect configuration drift and improve long-term cloud security maturity.
  • Executive-ready reporting and risk prioritization enable organizations to make informed security investment decisions.
  • Regular cloud security assessments, combined with penetration testing and continuous monitoring, form the foundation of a mature enterprise cloud security program.

➡️ Runbook 03 — Enterprise AWS Incident Response & Attack Path Investigation