Runbook 02 — Enterprise AWS Cloud Security Assessment
Runbook Information
Section titled “Runbook Information”| Item | Value |
|---|---|
| Module | Module 02 — AWS Cloud Penetration Testing |
| Runbook | 02 — Enterprise AWS Cloud Security Assessment |
| Audience | Cloud Security Engineers, Cloud Security Consultants, Red Teams, Blue Teams, Cloud Architects |
| Assessment Type | Enterprise Cloud Security Assessment |
| Estimated Duration | 3–10 Days |
| Frameworks | AWS Well-Architected Framework, CIS AWS Foundations Benchmark, NIST CSF, MITRE ATT&CK, ISO 27001, PCI DSS |
Objective
Section titled “Objective”This runbook provides a structured methodology for performing a complete enterprise AWS Cloud Security Assessment.
Unlike a penetration test, this assessment evaluates the overall security posture of the AWS environment by reviewing architecture, governance, configurations, identity, monitoring and operational security controls.
The assessment helps organizations answer:
- Is our AWS environment secure?
- What are our highest risks?
- Are security controls implemented correctly?
- Are we compliant with industry standards?
- How can we improve our cloud security posture?
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies has been engaged by FinSecure Bank Ltd to conduct an enterprise-wide AWS Cloud Security Assessment across multiple AWS accounts before a regulatory audit.
The environment includes:
- AWS Organizations
- 24 AWS Accounts
- Amazon EC2
- Amazon EKS
- AWS Lambda
- Amazon S3
- Amazon RDS
- AWS IAM Identity Center
- Security Hub
- GuardDuty
- AWS Config
- Security Lake
- Hybrid VPN Connectivity
Management requires a comprehensive security review and a prioritized remediation roadmap.
Assessment Methodology
Section titled “Assessment Methodology”Engagement Planning
↓
Architecture Review
↓
Identity Assessment
↓
Network Security Assessment
↓
Compute Security Assessment
↓
Storage Security Assessment
↓
Container Security Assessment
↓
Serverless Security Assessment
↓
Monitoring Assessment
↓
Governance Assessment
↓
Compliance Assessment
↓
Risk Analysis
↓
Reporting
↓
Executive PresentationPhase 1 — Engagement Planning
Section titled “Phase 1 — Engagement Planning”Objectives
Section titled “Objectives”Understand the enterprise environment before beginning the assessment.
Activities
Section titled “Activities”- Review project scope
- Confirm AWS accounts
- Identify AWS Regions
- Identify critical business applications
- Review architecture diagrams
- Confirm compliance requirements
- Review previous assessments
Deliverables
Section titled “Deliverables”- Assessment Scope
- Project Plan
- Asset List
- Rules of Engagement
Phase 2 — AWS Organization Assessment
Section titled “Phase 2 — AWS Organization Assessment”Review:
- AWS Organizations
- Organizational Units (OUs)
- Management Account
- Member Accounts
- Delegated Administrators
- Service Control Policies (SCPs)
- Account Separation
Questions
- Are production workloads isolated?
- Are SCPs implemented?
- Are development accounts separated?
Deliverables
Section titled “Deliverables”- AWS Organization Security Review
Phase 3 — Identity & Access Management Assessment
Section titled “Phase 3 — Identity & Access Management Assessment”Review:
- IAM Users
- IAM Roles
- IAM Groups
- IAM Policies
- Identity Center
- MFA
- Access Keys
- Trust Relationships
- Cross-Account Roles
Assess:
- Least privilege
- Administrator roles
- Privilege escalation
- Identity governance
Deliverables
Section titled “Deliverables”- IAM Security Assessment
Phase 4 — Network Security Assessment
Section titled “Phase 4 — Network Security Assessment”Review:
- Amazon VPC
- Public Subnets
- Private Subnets
- Route Tables
- Internet Gateways
- NAT Gateways
- Security Groups
- Network ACLs
- VPC Peering
- Transit Gateway
- PrivateLink
- DNS
Assess:
- Internet exposure
- Network segmentation
- Zero Trust implementation
- East-west traffic
Deliverables
Section titled “Deliverables”- Network Security Assessment
Phase 5 — Compute Security Assessment
Section titled “Phase 5 — Compute Security Assessment”Review:
- Amazon EC2
- Auto Scaling
- Launch Templates
- IMDS
- User Data
- EBS Encryption
- Instance Profiles
- Patch Management
- Systems Manager
Assess:
- Public instances
- Administrative access
- Operating system hardening
- Compute governance
Deliverables
Section titled “Deliverables”- EC2 Security Assessment
Phase 6 — Storage Security Assessment
Section titled “Phase 6 — Storage Security Assessment”Review:
- Amazon S3
- Amazon EBS
- Amazon EFS
- Amazon FSx
- AWS Backup
Assess:
- Encryption
- Public access
- Versioning
- Backup security
- Cross-account access
- Lifecycle policies
Deliverables
Section titled “Deliverables”- Storage Security Assessment
Phase 7 — Database Security Assessment
Section titled “Phase 7 — Database Security Assessment”Review:
- Amazon RDS
- Aurora
- DynamoDB
- Redshift
- ElastiCache
Assess:
- Encryption
- Authentication
- IAM integration
- Public accessibility
- Backup configuration
- Logging
Deliverables
Section titled “Deliverables”- Database Security Assessment
Phase 8 — Kubernetes Security Assessment
Section titled “Phase 8 — Kubernetes Security Assessment”Review:
- Amazon EKS
- RBAC
- Service Accounts
- IRSA
- Secrets
- ConfigMaps
- Network Policies
- Admission Controllers
- Worker Nodes
- Container Images
Assess:
- Cluster hardening
- Privileged workloads
- Pod Security
- Runtime security
Deliverables
Section titled “Deliverables”- Kubernetes Security Assessment
Phase 9 — Serverless Security Assessment
Section titled “Phase 9 — Serverless Security Assessment”Review:
- Lambda Functions
- Execution Roles
- Layers
- Event Sources
- Environment Variables
- Function URLs
- API Gateway
Assess:
- IAM permissions
- Secrets management
- Runtime security
- Dependency management
Deliverables
Section titled “Deliverables”- Serverless Security Assessment
Phase 10 — Logging & Monitoring Assessment
Section titled “Phase 10 — Logging & Monitoring Assessment”Review:
- CloudTrail
- CloudWatch
- AWS Config
- GuardDuty
- Security Hub
- Detective
- Security Lake
- VPC Flow Logs
- EKS Audit Logs
Assess:
- Detection capability
- Log retention
- Alerting
- SOC visibility
Deliverables
Section titled “Deliverables”- Logging & Monitoring Assessment
Phase 11 — Governance Assessment
Section titled “Phase 11 — Governance Assessment”Review:
- AWS Config Rules
- Security Hub Standards
- Tagging Strategy
- SCPs
- Backup Policies
- Change Management
- Patch Management
Assess:
- Governance maturity
- Policy enforcement
- Operational consistency
Deliverables
Section titled “Deliverables”- Cloud Governance Assessment
Phase 12 — Compliance Assessment
Section titled “Phase 12 — Compliance Assessment”Evaluate compliance against:
- CIS AWS Foundations Benchmark
- AWS Well-Architected Security Pillar
- ISO 27001
- PCI DSS
- NIST Cybersecurity Framework
Assess:
- Control implementation
- Evidence availability
- Compliance gaps
Deliverables
Section titled “Deliverables”- Compliance Gap Assessment
Phase 13 — Attack Surface Review
Section titled “Phase 13 — Attack Surface Review”Identify:
- Public EC2
- Public Load Balancers
- Public APIs
- Public S3 Buckets
- Public Lambda URLs
- Public Databases
- Exposed Kubernetes Services
Document:
- Internet-facing assets
- Business criticality
- Risk level
Deliverables
Section titled “Deliverables”- Internet Attack Surface Report
Phase 14 — Risk Analysis
Section titled “Phase 14 — Risk Analysis”Classify findings.
| Severity | Description |
|---|---|
| Critical | Immediate business impact |
| High | Significant enterprise risk |
| Medium | Moderate security weakness |
| Low | Minor issue |
| Informational | Best practice recommendation |
Prioritize based on:
- Likelihood
- Technical Impact
- Business Impact
- Regulatory Impact
Deliverables
Section titled “Deliverables”- Enterprise Risk Register
Phase 15 — Executive Dashboard
Section titled “Phase 15 — Executive Dashboard”| Metric | Example |
|---|---|
| AWS Accounts Reviewed | 24 |
| Critical Findings | 8 |
| High Findings | 19 |
| Medium Findings | 34 |
| Low Findings | 17 |
| IAM Roles Reviewed | 520 |
| EC2 Instances | 740 |
| S3 Buckets | 315 |
| EKS Clusters | 18 |
| Lambda Functions | 410 |
| Public Assets | 82 |
Phase 16 — Final Report
Section titled “Phase 16 — Final Report”The assessment report should contain:
Executive Summary
Section titled “Executive Summary”Business overview of the assessment.
- AWS Accounts
- Regions
- Services
- Applications
Methodology
Section titled “Methodology”Assessment standards followed.
Technical Findings
Section titled “Technical Findings”For each finding include:
- Description
- Evidence
- Business Impact
- Risk Rating
- Remediation
Architecture Review
Section titled “Architecture Review”Security architecture observations.
Compliance Mapping
Section titled “Compliance Mapping”Control mapping and compliance gaps.
Executive Recommendations
Section titled “Executive Recommendations”Immediate (0–30 Days)
- Enable MFA for privileged identities.
- Remove public access from sensitive resources.
- Restrict IAM permissions.
- Enable organization-wide CloudTrail.
Short-Term (30–90 Days)
- Harden EKS clusters.
- Implement least privilege.
- Improve monitoring.
- Enable Security Hub standards.
Long-Term (90–180 Days)
- Adopt Zero Trust Architecture.
- Implement continuous CSPM.
- Perform quarterly cloud security reviews.
- Automate compliance validation.
Enterprise Assessment Checklist
Section titled “Enterprise Assessment Checklist”| Assessment Area | Status |
|---|---|
| AWS Organizations | ☐ |
| IAM | ☐ |
| Networking | ☐ |
| EC2 | ☐ |
| Storage | ☐ |
| Databases | ☐ |
| Amazon EKS | ☐ |
| Lambda | ☐ |
| Logging | ☐ |
| Monitoring | ☐ |
| Governance | ☐ |
| Compliance | ☐ |
| Attack Surface | ☐ |
| Risk Register | ☐ |
| Executive Report | ☐ |
Deliverables
Section titled “Deliverables”At the end of the assessment, provide:
- Executive Summary
- Scope Document
- AWS Organization Review
- IAM Security Assessment
- Network Security Assessment
- Compute Security Assessment
- Storage Security Assessment
- Database Security Assessment
- Kubernetes Security Assessment
- Serverless Security Assessment
- Logging & Monitoring Assessment
- Governance Assessment
- Compliance Assessment
- Internet Attack Surface Report
- Enterprise Risk Register
- Executive Dashboard
- Final Cloud Security Assessment Report
- Executive Presentation
- Prioritized Remediation Roadmap
Success Criteria
Section titled “Success Criteria”The assessment is considered successful when:
- All in-scope AWS accounts and services have been reviewed.
- Security posture has been evaluated across identity, networking, compute, storage, Kubernetes and serverless workloads.
- Compliance gaps have been identified and documented.
- Business risks have been prioritized.
- Executive stakeholders receive a clear security maturity assessment and actionable remediation roadmap.
Key Takeaways
Section titled “Key Takeaways”- Enterprise cloud security assessments provide a holistic view of an organization’s AWS security posture beyond penetration testing alone.
- Identity, governance, networking, workloads, monitoring and compliance should be assessed together to understand overall risk.
- Continuous assessments help detect configuration drift and improve long-term cloud security maturity.
- Executive-ready reporting and risk prioritization enable organizations to make informed security investment decisions.
- Regular cloud security assessments, combined with penetration testing and continuous monitoring, form the foundation of a mature enterprise cloud security program.
Next Runbook
Section titled “Next Runbook”➡️ Runbook 03 — Enterprise AWS Incident Response & Attack Path Investigation