Lab 02 — Perform a Cloud Compliance Assessment
Mission Information
Section titled “Mission Information”| Field | Details |
|---|---|
| Lab Type | Cloud Compliance Assessment |
| Difficulty | Intermediate–Advanced |
| Estimated Time | 4–5 Hours |
| Primary Role | GRC Analyst / Cloud Compliance Analyst |
| Environment | Simulated Multi-Cloud Enterprise |
| Primary Standards | ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 |
| Primary Deliverable | Cloud Compliance Assessment Package |
Mission Scenario
Section titled “Mission Scenario”You are continuing your work with CloudNova Technologies.
In the previous lab, you created the organization’s Cloud Compliance Responsibility Matrix.
You documented:
Provider Responsibilities
Customer Responsibilities
Shared Controls
Inherited Controls
Internal Control Owners
Provider Evidence
Customer EvidenceManagement now wants to know whether those responsibilities are actually being fulfilled.
You have therefore been asked to perform a formal Cloud Compliance Assessment across CloudNova’s multi-cloud environment.
The environment includes:
AWS→ Production workloads
Azure→ Identity and enterprise services
Google Cloud→ Analytics workloads
SaaS→ HR, CRM, Support and collaboration platformsSeveral concerns have already been raised:
Some cloud accounts may not forward logs to SIEM.
Privileged access may not be consistently governed.
One SaaS platform may not enforce MFA.
Some data may be stored outside approved regions.
Provider assurance evidence may be outdated.
Recovery testing may not be consistently performed.Your mission is to determine:
Which cloud controls are effective, which are partially implemented, which have failed, what risks those gaps create, and what actions are required to restore compliance?
Mission Objectives
Section titled “Mission Objectives”By completing this lab, you will be able to:
-
Define a cloud compliance assessment scope.
-
Validate cloud inventories.
-
Review cloud provider assurance.
-
Review shared-responsibility mappings.
-
Build an evidence request list.
-
Test cloud IAM controls.
-
Test privileged access.
-
Assess workload identities.
-
Assess cloud logging.
-
Assess encryption.
-
Assess public exposure.
-
Assess secure configuration.
-
Assess data residency.
-
Assess backup and recovery.
-
Assess provider assurance freshness.
-
Assess SaaS controls.
-
Document cloud control findings.
-
Perform risk-impact analysis.
-
Perform root-cause analysis.
-
Build remediation actions.
-
Retest cloud controls.
-
Prepare an executive cloud-compliance summary.
Assessment Lifecycle
Section titled “Assessment Lifecycle”Define Scope ↓Validate Inventory ↓Review Responsibility Model ↓Review Provider Assurance ↓Request Evidence ↓Test IAM ↓Test Logging ↓Test Configuration ↓Test Encryption ↓Test Residency ↓Test Backup & Recovery ↓Assess SaaS ↓Document Findings ↓Evaluate Risk ↓Root Cause Analysis ↓Remediation ↓Retest ↓Executive ReportingLab Deliverables
Section titled “Lab Deliverables”Create the following artifacts:
Cloud-Compliance-Lab02/│├── 01-Cloud-Compliance-Assessment-Plan.md├── 02-Cloud-Evidence-Request-List.md├── 03-Cloud-Control-Testing-Worksheet.md├── 04-Cloud-Configuration-Assessment.md├── 05-Cloud-IAM-Assessment.md├── 06-Cloud-Logging-Assessment.md├── 07-Cloud-Data-Residency-Assessment.md├── 08-Cloud-Backup-Recovery-Assessment.md├── 09-Provider-Assurance-Assessment.md├── 10-SaaS-Compliance-Assessment.md├── 11-Cloud-Audit-Findings-Register.md├── 12-Cloud-Risk-Impact-Analysis.md├── 13-Cloud-Remediation-Tracker.md└── 14-Executive-Cloud-Compliance-Summary.mdPart 1 — Define the Assessment Scope
Section titled “Part 1 — Define the Assessment Scope”Step 1 — Create the Assessment Plan
Section titled “Step 1 — Create the Assessment Plan”Create:
01-Cloud-Compliance-Assessment-Plan.mdDocument:
Assessment Objective
Scope
Cloud Providers
Accounts / Subscriptions / Projects
SaaS Platforms
Data
Regions
Control Domains
Assessment Period
Criteria
StakeholdersStep 2 — Define Assessment Objective
Section titled “Step 2 — Define Assessment Objective”Use:
Determine whether CloudNova’s in-scope cloud security and compliance controls are appropriately designed, implemented, evidenced, and operating across its multi-cloud environment.
Step 3 — Define In-Scope Platforms
Section titled “Step 3 — Define In-Scope Platforms”Use the following lab scope:
AWS→ 8 Production Accounts
Azure→ 4 Production Subscriptions
Google Cloud→ 3 Production Projects
SaaS→ HR, CRM and Support PlatformsStep 4 — Define In-Scope Control Domains
Section titled “Step 4 — Define In-Scope Control Domains”Assess:
Cloud Governance
Provider Assurance
IAM
Privileged Access
Workload Identity
Logging
Network Security
Public Exposure
Encryption
Secure Configuration
Data Residency
Backup
Recovery
SaaS SecurityStep 5 — Define Assessment Criteria
Section titled “Step 5 — Define Assessment Criteria”Use:
CloudNova Cloud Security Policy
Cloud Configuration Baseline
Access Control Standard
Logging Standard
Data Residency Requirements
Backup & Recovery Standard
Cloud Responsibility Matrix
ISO/IEC 27017 Guidance
ISO/IEC 27018 Privacy ControlsPart 2 — Validate the Cloud Inventory
Section titled “Part 2 — Validate the Cloud Inventory”Step 6 — Review the Existing Inventory
Section titled “Step 6 — Review the Existing Inventory”Assume the inventory contains:
AWS Accounts: 8
Azure Subscriptions: 4
GCP Projects: 3
Critical SaaS Platforms: 3Expected total:
18 In-Scope Cloud EnvironmentsStep 7 — Validate Against Discovery Data
Section titled “Step 7 — Validate Against Discovery Data”The assessment identifies:
AWS:8 documented+ 1 undocumented sandbox account
Azure:4 documented
GCP:3 documented
SaaS:3 documented+ 1 unsanctioned marketing SaaSResult:
Documented:18
Actual:20Inventory coverage:
90%Step 8 — Document Inventory Gap
Section titled “Step 8 — Document Inventory Gap”Finding candidate:
Two active cloud services were not recorded in the approved Cloud Service Inventory.
Potential risk:
Unmanaged access
Unknown data
Missing logging
Unknown residency
Unassessed vendor riskStep 9 — Determine Severity
Section titled “Step 9 — Determine Severity”Because one undocumented SaaS service contains customer contact information, classify the gap as:
Highfor this lab.
Part 3 — Build the Evidence Request List
Section titled “Part 3 — Build the Evidence Request List”Step 10 — Create
Section titled “Step 10 — Create”02-Cloud-Evidence-Request-List.mdUse:
| Request ID | Evidence | Owner | Due | Status |
|---|
Step 11 — Request Governance Evidence
Section titled “Step 11 — Request Governance Evidence”Request:
Cloud Inventory
Responsibility Matrix
Approved Region Register
Cloud Control Framework
Exception RegisterStep 12 — Request IAM Evidence
Section titled “Step 12 — Request IAM Evidence”Request:
Privileged User Inventory
MFA Coverage
Access Reviews
Service Account Inventory
Break-Glass Account RegisterStep 13 — Request Logging Evidence
Section titled “Step 13 — Request Logging Evidence”Request:
Log Source Inventory
SIEM Coverage Report
Retention Configuration
Logging ExceptionsStep 14 — Request Configuration Evidence
Section titled “Step 14 — Request Configuration Evidence”Request:
CSPM Report
Public Resource Report
Encryption Coverage
Security Baseline Report
Network Exposure ReportStep 15 — Request Provider Evidence
Section titled “Step 15 — Request Provider Evidence”Request:
ISO Certificates
SOC Reports
Provider Responsibility Documentation
Incident Terms
Subprocessor ListsStep 16 — Request Resilience Evidence
Section titled “Step 16 — Request Resilience Evidence”Request:
Backup Reports
Recovery Test Reports
DR Test Reports
Backup ExceptionsPart 4 — Review Shared Responsibility
Section titled “Part 4 — Review Shared Responsibility”Step 17 — Select Control Areas
Section titled “Step 17 — Select Control Areas”Review:
Physical Security
IAM
Logging
Encryption
Backup
Incident Response
Data ResidencyStep 18 — Validate Responsibility Type
Section titled “Step 18 — Validate Responsibility Type”For each control confirm:
Provider
Customer
Shared
InheritedStep 19 — Sample Responsibility Matrix
Section titled “Step 19 — Sample Responsibility Matrix”| Control | Responsibility |
|---|---|
| Physical Security | Inherited |
| Privileged MFA | Shared |
| Logging | Shared |
| Guest OS Patching | Customer |
| Backup | Shared |
| Provider Incident Response | Shared |
| Data Region Selection | Shared |
Step 20 — Test Internal Ownership
Section titled “Step 20 — Test Internal Ownership”Verify every shared control has an internal owner.
Expected gap:
SaaS Data Deletion→ No clear internal ownerDocument as governance weakness.
Part 5 — Assess Provider Assurance
Section titled “Part 5 — Assess Provider Assurance”Step 21 — Create
Section titled “Step 21 — Create”09-Provider-Assurance-Assessment.mdReview five critical providers.
Use:
| Provider | Service | Evidence | Age | Scope | Status |
|---|
Step 22 — Lab Evidence
Section titled “Step 22 — Lab Evidence”Assume:
Provider A→ Current ISO certificate
Provider B→ Current SOC 2
Provider C→ SOC 2 is 18 months old
Provider D→ Current ISO 27001
Provider E→ No recent assurance reportStep 23 — Evaluate Evidence Freshness
Section titled “Step 23 — Evaluate Evidence Freshness”Use:
CurrentApproaching ExpiryStaleUnavailableResult:
Provider C→ Stale
Provider E→ UnavailableStep 24 — Review Scope
Section titled “Step 24 — Review Scope”For Provider C:
Report covers:Core SaaS Platform
Does not cover:New AI Analytics FeatureDocument:
Current assurance does not cover a newly enabled service feature processing customer data.
Step 25 — Provider Finding
Section titled “Step 25 — Provider Finding”Requirement:
Critical cloud providers must have current risk-appropriate assurance evidence.
Condition:
Two of five critical providers do not have current complete assurance evidence.
Risk:
Provider control weaknessesmay remain unidentified.Part 6 — Assess Cloud IAM
Section titled “Part 6 — Assess Cloud IAM”Step 26 — Create
Section titled “Step 26 — Create”05-Cloud-IAM-Assessment.mdStep 27 — Review Privileged Population
Section titled “Step 27 — Review Privileged Population”Assume:
Privileged Human Identities:64MFA enabled:
61MFA coverage:
95.3%Expected:
100%Step 28 — Investigate the Three Failures
Section titled “Step 28 — Investigate the Three Failures”Find:
User 1→ Emergency administrator
User 2→ Legacy local account
User 3→ SaaS super administratorStep 29 — Evaluate Emergency Account
Section titled “Step 29 — Evaluate Emergency Account”Emergency account:
Approved:Yes
Strong credential:Yes
MFA:Not enabled
Compensating monitoring:YesThe enterprise control still requires strong authentication.
Status:
Exception RequiredNo approved exception exists.
Step 30 — Evaluate Legacy Local Account
Section titled “Step 30 — Evaluate Legacy Local Account”Finding:
Local cloud administratorbypasses federation and MFA.Risk:
Credential compromiseStep 31 — Evaluate SaaS Super Administrator
Section titled “Step 31 — Evaluate SaaS Super Administrator”Provider supports MFA.
Customer has not enabled it.
This is a clear shared-responsibility failure.
Step 32 — Privileged MFA Finding
Section titled “Step 32 — Privileged MFA Finding”Write:
The Privileged Access Standard requires MFA for all privileged human cloud accounts. Three of sixty-four privileged accounts did not meet the requirement, including one legacy cloud administrator and one SaaS super administrator. No approved exceptions were recorded.
Step 33 — Access Review Testing
Section titled “Step 33 — Access Review Testing”Requirement:
Quarterly privileged access reviewEvidence:
Q1:Complete
Q2:Complete
Q3:Missing for Azure
Q4:Not Yet DueConclusion:
Partially EffectivePart 7 — Assess Workload Identities
Section titled “Part 7 — Assess Workload Identities”Step 34 — Review Service Accounts
Section titled “Step 34 — Review Service Accounts”Population:
142 workload identitiesFind:
14 use long-lived static credentials
5 credentials older than 365 days
2 have administrator-equivalent accessStep 35 — Evaluate Control
Section titled “Step 35 — Evaluate Control”Enterprise standard:
Managed or short-lived workload identities must be used where supported, and workload privileges must follow least privilege.
Conclusion:
Partially ImplementedStep 36 — Workload Identity Finding
Section titled “Step 36 — Workload Identity Finding”Risk:
Static credential compromise
Excessive machine privilegeRecommended treatment:
Replace static credentials
Use managed identities / roles
Reduce permissions
Establish credential-age monitoringPart 8 — Assess Logging
Section titled “Part 8 — Assess Logging”Step 37 — Create
Section titled “Step 37 — Create”06-Cloud-Logging-Assessment.mdStep 38 — Evaluate Production Coverage
Section titled “Step 38 — Evaluate Production Coverage”Population:
15 IaaS / PaaS production environmentsForwarding to SIEM:
13Coverage:
86.7%Step 39 — Missing Environments
Section titled “Step 39 — Missing Environments”Find:
AWS Account 7→ Audit logs enabled locally→ Not forwarded to SIEM
GCP Project 3→ Audit logs partially enabledStep 40 — Evaluate Log Retention
Section titled “Step 40 — Evaluate Log Retention”Requirement:
365 daysActual:
AWS:365
Azure:365
GCP:90 daysFinding:
GCP retention below standardStep 41 — Logging Finding
Section titled “Step 41 — Logging Finding”Write:
Central administrative logging is incomplete. Two production environments are not fully integrated with the enterprise SIEM, and one GCP environment retains required audit logs for only 90 days rather than the 365-day standard.
Step 42 — Review Detection
Section titled “Step 42 — Review Detection”Select three events:
New Admin Role
Logging Disabled
Public Storage ChangeResults:
Admin Role→ Alert configured
Logging Disabled→ Alert configured
Public Storage Change→ No detection ruleDocument detection gap.
Part 9 — Assess Cloud Configuration
Section titled “Part 9 — Assess Cloud Configuration”Step 43 — Create
Section titled “Step 43 — Create”04-Cloud-Configuration-Assessment.mdAssess the fictional population:
Storage Resources:120
Databases:35
Compute Workloads:75
Production Networks:15Step 44 — Public Storage Test
Section titled “Step 44 — Public Storage Test”Requirement:
Production storage must not permit unauthorized public access.
Find:
120 Resources
Public:3Review:
Resource 1→ Approved public website asset
Resource 2→ No exception
Resource 3→ No exceptionResult:
2 unauthorized public resourcesStep 45 — Open Administrative Ports
Section titled “Step 45 — Open Administrative Ports”Requirement:
No unrestricted management portsFind:
2 security groupsallow SSH from 0.0.0.0/0No approved exceptions.
Step 46 — Secure Baseline Coverage
Section titled “Step 46 — Secure Baseline Coverage”Population:
75 compute workloadsCompliant:
68Noncompliant:
7Gaps include:
Missing endpoint agent
Outdated image
Weak host firewallPart 10 — Assess Encryption
Section titled “Part 10 — Assess Encryption”Step 47 — Review Storage Encryption
Section titled “Step 47 — Review Storage Encryption”Population:
155 storage and database resourcesEncrypted:
153Unencrypted:
2Step 48 — Investigate
Section titled “Step 48 — Investigate”Both unencrypted resources contain:
Internal-only test databut baseline requires encryption for all cloud storage.
Conclusion:
Control FailureSeverity:
Mediumfor this lab.
Step 49 — Review Key Access
Section titled “Step 49 — Review Key Access”Customer-managed keys:
18Find:
3 keys allow broad administrative accessRisk:
Unauthorized key usePart 11 — Assess Data Residency
Section titled “Part 11 — Assess Data Residency”Step 50 — Create
Section titled “Step 50 — Create”07-Cloud-Data-Residency-Assessment.mdStep 51 — Review Restricted Data
Section titled “Step 51 — Review Restricted Data”Population:
25 Restricted datasetsApproved region:
EUFind:
23→ EU
1→ US analytics copy
1→ Singapore backupStep 52 — Review Transfer Approvals
Section titled “Step 52 — Review Transfer Approvals”US analytics copy:
Approved transfer:Yes
Current:YesSingapore backup:
Approved:NoStep 53 — Residency Finding
Section titled “Step 53 — Residency Finding”Write:
One backup containing Restricted customer data is stored in a region not listed in the Approved Cloud Region Register and has no approved residency exception.
Step 54 — Review SaaS Support Access
Section titled “Step 54 — Review SaaS Support Access”HR SaaS:
Primary:EU
Provider support:GlobalContract review shows support access is controlled but not restricted to EU.
Document as:
Risk Review Requirednot automatically a control failure.
Part 12 — Assess Backup & Recovery
Section titled “Part 12 — Assess Backup & Recovery”Step 55 — Create
Section titled “Step 55 — Create”08-Cloud-Backup-Recovery-Assessment.mdStep 56 — Review Backup Coverage
Section titled “Step 56 — Review Backup Coverage”Critical workloads:
20Backup configured:
20Coverage:
100%Step 57 — Review Recovery Testing
Section titled “Step 57 — Review Recovery Testing”Requirement:
QuarterlyEvidence:
16 workloads→ Current recovery test
4 workloads→ No test in last 12 monthsStep 58 — Assess Recovery Findings
Section titled “Step 58 — Assess Recovery Findings”Backups exist.
But:
Recoverability→ Not demonstrated for 4 workloadsFinding:
Four critical workloads have not undergone required recovery testing within the established testing period.
Step 59 — Review Backup Failure Monitoring
Section titled “Step 59 — Review Backup Failure Monitoring”Find:
Failure alerts:Configured for 18/20 workloadsTwo workloads rely on manual review.
Document improvement opportunity or finding based on lab assessment.
Part 13 — Assess SaaS Compliance
Section titled “Part 13 — Assess SaaS Compliance”Step 60 — Create
Section titled “Step 60 — Create”10-SaaS-Compliance-Assessment.mdAssess:
HR SaaS
CRM SaaS
Support SaaSStep 61 — HR SaaS
Section titled “Step 61 — HR SaaS”Findings:
MFA:Not mandatory for 1 super admin
External sharing:Not applicable
Retention:Configured
Provider assurance:CurrentStep 62 — CRM SaaS
Section titled “Step 62 — CRM SaaS”Findings:
MFA:100%
External sharing:12 guest users
4 guest accounts inactive > 180 days
Audit logs:EnabledPotential finding:
Dormant guest accountsStep 63 — Support SaaS
Section titled “Step 63 — Support SaaS”Findings:
Provider assurance:Stale
Logs:Available but not exported to SIEM
Customer PII:YesThis creates combined vendor and monitoring risk.
Step 64 — SaaS Integration Review
Section titled “Step 64 — SaaS Integration Review”Find:
CRM→ 18 OAuth integrationsThree have:
Unknown ownerDocument:
Three active third-party SaaS integrations do not have documented business or technical owners.
Part 14 — Build the Control Testing Worksheet
Section titled “Part 14 — Build the Control Testing Worksheet”Step 65 — Create
Section titled “Step 65 — Create”03-Cloud-Control-Testing-Worksheet.mdUse:
| Control | Requirement | Population | Test | Result | Conclusion |
|---|
Step 66 — Sample Entries
Section titled “Step 66 — Sample Entries”| Control | Population | Result |
|---|---|---|
| Privileged MFA | 64 | 61 Pass / 3 Fail |
| SIEM Logging | 15 | 13 Pass / 2 Fail |
| Encryption | 155 | 153 Pass / 2 Fail |
| Approved Region | 25 | 24 Pass / 1 Fail |
| Backup Recovery | 20 | 16 Pass / 4 Fail |
Step 67 — Use Standard Conclusions
Section titled “Step 67 — Use Standard Conclusions”Use:
Effective
Partially Effective
Ineffective
Not TestedPart 15 — Build the Findings Register
Section titled “Part 15 — Build the Findings Register”Step 68 — Create
Section titled “Step 68 — Create”11-Cloud-Audit-Findings-Register.mdUse:
| ID | Finding | Control | Risk | Severity | Owner | Status |
|---|
Step 69 — Finding 01
Section titled “Step 69 — Finding 01”F-001Cloud Inventory IncompleteSeverity:
HighStep 70 — Finding 02
Section titled “Step 70 — Finding 02”F-002Privileged MFA GapsSeverity:
HighStep 71 — Finding 03
Section titled “Step 71 — Finding 03”F-003Incomplete Central LoggingSeverity:
HighStep 72 — Finding 04
Section titled “Step 72 — Finding 04”F-004Unauthorized Public Cloud ResourcesSeverity:
HighStep 73 — Finding 05
Section titled “Step 73 — Finding 05”F-005Restricted Backup in Unauthorized RegionSeverity:
HighStep 74 — Finding 06
Section titled “Step 74 — Finding 06”F-006Recovery Testing OverdueSeverity:
HighStep 75 — Finding 07
Section titled “Step 75 — Finding 07”F-007Stale Provider AssuranceSeverity:
Medium / HighStep 76 — Finding 08
Section titled “Step 76 — Finding 08”F-008Long-Lived Workload CredentialsSeverity:
MediumPart 16 — Build Risk Impact Analysis
Section titled “Part 16 — Build Risk Impact Analysis”Step 77 — Create
Section titled “Step 77 — Create”12-Cloud-Risk-Impact-Analysis.mdUse:
| Finding | Related Risk | Current Risk | Impact |
|---|
Step 78 — Example
Section titled “Step 78 — Example”F-002Privileged MFA GapRisk:
Cloud administrator compromiseCurrent rating:
HighImpact:
Unauthorized administrative accessStep 79 — Logging Risk
Section titled “Step 79 — Logging Risk”F-003Risk:
Security events remain undetectedResidual rating:
HighStep 80 — Residency Risk
Section titled “Step 80 — Residency Risk”F-005Risk:
Contractual / privacy violationResidual rating:
HighPart 17 — Perform Root Cause Analysis
Section titled “Part 17 — Perform Root Cause Analysis”Step 81 — Inventory Finding
Section titled “Step 81 — Inventory Finding”Problem:
Undocumented cloud environmentsWhy?
Business teams can purchase cloud services directly.Why?
Procurement process does not require cloud-security approval.Root cause:
Cloud-service procurement is not consistently integrated with the formal cloud onboarding process.
Step 82 — MFA Finding
Section titled “Step 82 — MFA Finding”Problem:
Privileged users without MFARoot cause:
Legacy and SaaS administrator accounts are not included in the centralized privileged-identity control process.
Step 83 — Logging Finding
Section titled “Step 83 — Logging Finding”Problem:
New accounts missing SIEM integrationRoot cause:
Account provisioning does not automatically deploy centralized logging.
Step 84 — Public Exposure Finding
Section titled “Step 84 — Public Exposure Finding”Problem:
Resources publicly accessibleRoot cause:
Public-access prevention is detective rather than preventive.
Step 85 — Residency Finding
Section titled “Step 85 — Residency Finding”Problem:
Backup deployed in unauthorized regionRoot cause:
Backup configuration is not validated against approved residency requirements.
Step 86 — Recovery Finding
Section titled “Step 86 — Recovery Finding”Problem:
Tests overdueRoot cause:
Recovery-test scheduling is manually maintained and lacks escalation.
Part 18 — Build the Remediation Tracker
Section titled “Part 18 — Build the Remediation Tracker”Step 87 — Create
Section titled “Step 87 — Create”13-Cloud-Remediation-Tracker.mdUse:
| Finding | Correction | Corrective Action | Owner | Target | Retest |
|---|
Step 88 — F-001 Remediation
Section titled “Step 88 — F-001 Remediation”Correction:
Add missing services to inventory.Corrective action:
Require procurement and SSO integration workflows to trigger cloud-security onboarding review.
Step 89 — F-002 Remediation
Section titled “Step 89 — F-002 Remediation”Correction:
Enable MFA on three privileged accounts.Corrective action:
Extend enterprise privileged-identity monitoring to local and SaaS administrator accounts.
Step 90 — F-003 Remediation
Section titled “Step 90 — F-003 Remediation”Correction:
Connect missing environments to SIEM.Corrective action:
Automate centralized logging as part of account/project/subscription provisioning.
Step 91 — F-004 Remediation
Section titled “Step 91 — F-004 Remediation”Correction:
Remove unauthorized public access.Corrective action:
Implement preventive policy-as-code controls blocking unapproved public storage.
Step 92 — F-005 Remediation
Section titled “Step 92 — F-005 Remediation”Correction:
Move backup to approved region.Corrective action:
Add residency validation to backup policy and deployment controls.
Step 93 — F-006 Remediation
Section titled “Step 93 — F-006 Remediation”Correction:
Perform recovery tests.Corrective action:
Implement centralized recovery-test scheduling, reminders, escalation, and reporting.
Step 94 — F-007 Remediation
Section titled “Step 94 — F-007 Remediation”Correction:
Obtain current provider assurance.Corrective action:
Implement provider-assurance freshness monitoring and escalation.
Part 19 — Perform Retesting
Section titled “Part 19 — Perform Retesting”Step 95 — Define Retest Requirements
Section titled “Step 95 — Define Retest Requirements”A finding should not close simply because:
Owner says fixed.Verify:
Correction
Corrective Action
Full Population
Latest Evidence
Recurrence PreventionStep 96 — Retest MFA
Section titled “Step 96 — Retest MFA”Expected:
64 / 64 privileged userswith approved MFAStep 97 — Retest Logging
Section titled “Step 97 — Retest Logging”Expected:
15 / 15 production environmentsconnected to SIEMAlso verify:
new account provisioningautomatically enables loggingStep 98 — Retest Public Exposure
Section titled “Step 98 — Retest Public Exposure”Expected:
0 unauthorized public resourcesand:
policy-as-code enforcement activeStep 99 — Retest Residency
Section titled “Step 99 — Retest Residency”Expected:
25 / 25 Restricted datasetsin approved regionsor covered by approved exceptionStep 100 — Retest Recovery
Section titled “Step 100 — Retest Recovery”Expected:
20 / 20 critical workloadswith current recovery testsPart 20 — Update Control Status
Section titled “Part 20 — Update Control Status”After assessment, assign statuses.
Example:
| Control | Status |
|---|---|
| Cloud Inventory | Partially Effective |
| Privileged MFA | Partially Effective |
| Logging | Partially Effective |
| Encryption | Effective with Minor Gap |
| Data Residency | Partially Effective |
| Backup Configuration | Effective |
| Recovery Testing | Partially Effective |
| Provider Assurance | Partially Effective |
Part 21 — Update Risk and Compliance Artifacts
Section titled “Part 21 — Update Risk and Compliance Artifacts”Step 101 — Update Risk Register
Section titled “Step 101 — Update Risk Register”Where relevant:
Finding ↓Risk Rating ↓Treatment PlanStep 102 — Update Responsibility Matrix
Section titled “Step 102 — Update Responsibility Matrix”If the assessment reveals ambiguity:
Clarify Provider Activity
Clarify Customer Activity
Assign Internal OwnerStep 103 — Update SoA / Control Library
Section titled “Step 103 — Update SoA / Control Library”Where cloud control status changed:
Implemented ↓Partially Implementedif appropriate.
Step 104 — Update Exception Register
Section titled “Step 104 — Update Exception Register”Any accepted deviation must include:
Risk
Owner
Approver
Compensating Control
ExpiryPart 22 — Build Executive Summary
Section titled “Part 22 — Build Executive Summary”Step 105 — Create
Section titled “Step 105 — Create”14-Executive-Cloud-Compliance-Summary.mdStep 106 — Include Overall Assessment
Section titled “Step 106 — Include Overall Assessment”Use:
Overall Cloud Compliance Status:Partially EffectiveStep 107 — Example Executive Dashboard
Section titled “Step 107 — Example Executive Dashboard”| Metric | Result |
|---|---|
| Cloud Environments Identified | 20 |
| Inventory Coverage | 90% |
| Privileged MFA Coverage | 95.3% |
| SIEM Coverage | 86.7% |
| Encryption Coverage | 98.7% |
| Approved Residency Coverage | 96% |
| Recovery Testing Coverage | 80% |
| High Findings | 6 |
| Medium Findings | 2 |
Step 108 — Top Risks
Section titled “Step 108 — Top Risks”Highlight:
Privileged Access
Logging Gaps
Unauthorized Public Exposure
Data Residency
Recovery Readiness
Provider AssuranceStep 109 — Executive Recommendation
Section titled “Step 109 — Executive Recommendation”Use:
CloudNova has established a strong cloud governance and shared-responsibility foundation, but the assessment identified material operational gaps in inventory completeness, privileged authentication, centralized logging, public exposure prevention, data residency, recovery testing, and provider assurance. Priority remediation should focus on converting manual controls into standardized and automated cloud guardrails.
Part 23 — Management Action Plan
Section titled “Part 23 — Management Action Plan”Recommend:
Priority 1→ Privileged MFA
Priority 2→ Centralized Logging
Priority 3→ Public Exposure Prevention
Priority 4→ Residency Enforcement
Priority 5→ Recovery Testing
Priority 6→ Provider Assurance AutomationPart 24 — Assessment Quality Review
Section titled “Part 24 — Assessment Quality Review”Before closing, ask:
Did we validate the full cloud inventory?
Did we understand shared responsibility?
Did we review provider evidence?
Did we test customer controls?
Did we test complete populations where possible?
Did we review SaaS?
Did we review residency?
Did we test recovery?
Did we identify root causes?
Did we define sustainable corrective actions?
Can findings be independently retested?Final Lab Deliverables
Section titled “Final Lab Deliverables”Your completed folder should contain:
Cloud-Compliance-Lab02/│├── 01-Cloud-Compliance-Assessment-Plan.md├── 02-Cloud-Evidence-Request-List.md├── 03-Cloud-Control-Testing-Worksheet.md├── 04-Cloud-Configuration-Assessment.md├── 05-Cloud-IAM-Assessment.md├── 06-Cloud-Logging-Assessment.md├── 07-Cloud-Data-Residency-Assessment.md├── 08-Cloud-Backup-Recovery-Assessment.md├── 09-Provider-Assurance-Assessment.md├── 10-SaaS-Compliance-Assessment.md├── 11-Cloud-Audit-Findings-Register.md├── 12-Cloud-Risk-Impact-Analysis.md├── 13-Cloud-Remediation-Tracker.md└── 14-Executive-Cloud-Compliance-Summary.mdLab Completion Checklist
Section titled “Lab Completion Checklist”-
Assessment objective defined.
-
Cloud platforms scoped.
-
SaaS included.
-
Control domains identified.
-
Criteria defined.
Inventory
Section titled “Inventory”-
Inventory validated.
-
Unknown environments identified.
-
Owners validated.
-
Data classifications reviewed.
Provider Assurance
Section titled “Provider Assurance”-
Critical providers identified.
-
Assurance evidence collected.
-
Evidence freshness reviewed.
-
Scope validated.
-
Provider exceptions reviewed.
-
Privileged population identified.
-
MFA tested.
-
Federation reviewed.
-
Access reviews tested.
-
Workload identities assessed.
-
Static credentials reviewed.
Logging
Section titled “Logging”-
Logging coverage measured.
-
SIEM integration reviewed.
-
Retention reviewed.
-
Detection coverage tested.
-
Log protection considered.
Configuration
Section titled “Configuration”-
Public storage assessed.
-
Management ports assessed.
-
Compute baseline assessed.
-
Network exposure reviewed.
-
Policy-as-code reviewed.
Data Protection
Section titled “Data Protection”-
Encryption coverage tested.
-
Key access reviewed.
-
Exceptions identified.
Residency
Section titled “Residency”-
Restricted datasets identified.
-
Primary regions reviewed.
-
Backups reviewed.
-
Transfers reviewed.
-
SaaS support locations considered.
Backup & Recovery
Section titled “Backup & Recovery”-
Backup coverage assessed.
-
Recovery testing assessed.
-
Failure monitoring reviewed.
-
MFA assessed.
-
Guest users reviewed.
-
External sharing reviewed.
-
Integrations reviewed.
-
Provider assurance reviewed.
Findings
Section titled “Findings”-
Requirements identified.
-
Conditions documented.
-
Evidence recorded.
-
Risks described.
-
Severity assigned.
-
Owners assigned.
Remediation
Section titled “Remediation”-
Corrections defined.
-
Root causes identified.
-
Corrective actions defined.
-
Targets assigned.
-
Retest evidence defined.
Skills You Practiced
Section titled “Skills You Practiced”By completing this lab, you practiced:
Cloud Audit Planning
Cloud Inventory Validation
Provider Assurance Review
Shared Responsibility Testing
IAM Assessment
Privileged Access Testing
Workload Identity Assessment
Cloud Logging Assessment
Configuration Assessment
Encryption Assessment
Residency Assessment
Recovery Assessment
SaaS Compliance Assessment
Audit Evidence Analysis
Finding Writing
Root Cause Analysis
Risk Impact Analysis
Remediation Planning
Cloud Retesting
Executive ReportingThese are practical skills used by:
-
Cloud GRC Analysts.
-
Cloud Compliance Analysts.
-
Security Assurance Analysts.
-
Internal Auditors.
-
ISO Cloud Security Consultants.
-
Cloud Security Governance Analysts.
-
Third-Party Risk Analysts.
Portfolio Challenge
Section titled “Portfolio Challenge”Package your work as:
CloudNova TechnologiesMulti-Cloud Compliance AssessmentInclude:
Executive Summary
Assessment Scope
Cloud Inventory
Provider Assurance Review
IAM Assessment
Logging Assessment
Configuration Assessment
Data Residency Assessment
Backup & Recovery Assessment
SaaS Assessment
Findings Register
Risk Impact Analysis
Remediation PlanDo not use confidential information from a real employer or customer in a public portfolio.
Mission Complete
Section titled “Mission Complete”You have now moved from:
Cloud Responsibility Definedto:
Cloud Responsibility Tested ↓Evidence Validated ↓Gaps Identified ↓Risk Assessed ↓Root Cause Identified ↓Remediation Planned ↓Retest DefinedThis is the complete operational lifecycle of a practical cloud compliance assessment.
What’s Next?
Section titled “What’s Next?”➡️ Next: Runbook 01 — Cloud Compliance Assessment & Evidence Collection
In the next activity, you will turn the assessment methodology into a repeatable enterprise runbook covering:
Assessment Trigger ↓Scope Definition ↓Cloud Inventory Validation ↓Provider Assurance Collection ↓Shared Responsibility Review ↓Evidence Request ↓Control Testing ↓Finding Management ↓Risk Update ↓Remediation ↓Retesting ↓Management ReportingThe runbook will give GRC and cloud compliance teams a reusable procedure for performing periodic and event-driven cloud compliance assessments across IaaS, PaaS, SaaS, and multi-cloud environments.