Skip to content

Lab 02 — Perform a Cloud Compliance Assessment

Field Details
Lab Type Cloud Compliance Assessment
Difficulty Intermediate–Advanced
Estimated Time 4–5 Hours
Primary Role GRC Analyst / Cloud Compliance Analyst
Environment Simulated Multi-Cloud Enterprise
Primary Standards ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018
Primary Deliverable Cloud Compliance Assessment Package

You are continuing your work with CloudNova Technologies.

In the previous lab, you created the organization’s Cloud Compliance Responsibility Matrix.

You documented:

Provider Responsibilities
Customer Responsibilities
Shared Controls
Inherited Controls
Internal Control Owners
Provider Evidence
Customer Evidence

Management now wants to know whether those responsibilities are actually being fulfilled.

You have therefore been asked to perform a formal Cloud Compliance Assessment across CloudNova’s multi-cloud environment.

The environment includes:

AWS
→ Production workloads
Azure
→ Identity and enterprise services
Google Cloud
→ Analytics workloads
SaaS
→ HR, CRM, Support and collaboration platforms

Several concerns have already been raised:

Some cloud accounts may not forward logs to SIEM.
Privileged access may not be consistently governed.
One SaaS platform may not enforce MFA.
Some data may be stored outside approved regions.
Provider assurance evidence may be outdated.
Recovery testing may not be consistently performed.

Your mission is to determine:

Which cloud controls are effective, which are partially implemented, which have failed, what risks those gaps create, and what actions are required to restore compliance?

By completing this lab, you will be able to:

  • Define a cloud compliance assessment scope.

  • Validate cloud inventories.

  • Review cloud provider assurance.

  • Review shared-responsibility mappings.

  • Build an evidence request list.

  • Test cloud IAM controls.

  • Test privileged access.

  • Assess workload identities.

  • Assess cloud logging.

  • Assess encryption.

  • Assess public exposure.

  • Assess secure configuration.

  • Assess data residency.

  • Assess backup and recovery.

  • Assess provider assurance freshness.

  • Assess SaaS controls.

  • Document cloud control findings.

  • Perform risk-impact analysis.

  • Perform root-cause analysis.

  • Build remediation actions.

  • Retest cloud controls.

  • Prepare an executive cloud-compliance summary.

Define Scope
Validate Inventory
Review Responsibility Model
Review Provider Assurance
Request Evidence
Test IAM
Test Logging
Test Configuration
Test Encryption
Test Residency
Test Backup & Recovery
Assess SaaS
Document Findings
Evaluate Risk
Root Cause Analysis
Remediation
Retest
Executive Reporting

Create the following artifacts:

Cloud-Compliance-Lab02/
├── 01-Cloud-Compliance-Assessment-Plan.md
├── 02-Cloud-Evidence-Request-List.md
├── 03-Cloud-Control-Testing-Worksheet.md
├── 04-Cloud-Configuration-Assessment.md
├── 05-Cloud-IAM-Assessment.md
├── 06-Cloud-Logging-Assessment.md
├── 07-Cloud-Data-Residency-Assessment.md
├── 08-Cloud-Backup-Recovery-Assessment.md
├── 09-Provider-Assurance-Assessment.md
├── 10-SaaS-Compliance-Assessment.md
├── 11-Cloud-Audit-Findings-Register.md
├── 12-Cloud-Risk-Impact-Analysis.md
├── 13-Cloud-Remediation-Tracker.md
└── 14-Executive-Cloud-Compliance-Summary.md

Create:

01-Cloud-Compliance-Assessment-Plan.md

Document:

Assessment Objective
Scope
Cloud Providers
Accounts / Subscriptions / Projects
SaaS Platforms
Data
Regions
Control Domains
Assessment Period
Criteria
Stakeholders

Use:

Determine whether CloudNova’s in-scope cloud security and compliance controls are appropriately designed, implemented, evidenced, and operating across its multi-cloud environment.

Use the following lab scope:

AWS
→ 8 Production Accounts
Azure
→ 4 Production Subscriptions
Google Cloud
→ 3 Production Projects
SaaS
→ HR, CRM and Support Platforms

Step 4 — Define In-Scope Control Domains

Section titled “Step 4 — Define In-Scope Control Domains”

Assess:

Cloud Governance
Provider Assurance
IAM
Privileged Access
Workload Identity
Logging
Network Security
Public Exposure
Encryption
Secure Configuration
Data Residency
Backup
Recovery
SaaS Security

Use:

CloudNova Cloud Security Policy
Cloud Configuration Baseline
Access Control Standard
Logging Standard
Data Residency Requirements
Backup & Recovery Standard
Cloud Responsibility Matrix
ISO/IEC 27017 Guidance
ISO/IEC 27018 Privacy Controls

Assume the inventory contains:

AWS Accounts: 8
Azure Subscriptions: 4
GCP Projects: 3
Critical SaaS Platforms: 3

Expected total:

18 In-Scope Cloud Environments

Step 7 — Validate Against Discovery Data

Section titled “Step 7 — Validate Against Discovery Data”

The assessment identifies:

AWS:
8 documented
+ 1 undocumented sandbox account
Azure:
4 documented
GCP:
3 documented
SaaS:
3 documented
+ 1 unsanctioned marketing SaaS

Result:

Documented:
18
Actual:
20

Inventory coverage:

90%

Finding candidate:

Two active cloud services were not recorded in the approved Cloud Service Inventory.

Potential risk:

Unmanaged access
Unknown data
Missing logging
Unknown residency
Unassessed vendor risk

Because one undocumented SaaS service contains customer contact information, classify the gap as:

High

for this lab.

Part 3 — Build the Evidence Request List

Section titled “Part 3 — Build the Evidence Request List”
02-Cloud-Evidence-Request-List.md

Use:

Request ID Evidence Owner Due Status

Request:

Cloud Inventory
Responsibility Matrix
Approved Region Register
Cloud Control Framework
Exception Register

Request:

Privileged User Inventory
MFA Coverage
Access Reviews
Service Account Inventory
Break-Glass Account Register

Request:

Log Source Inventory
SIEM Coverage Report
Retention Configuration
Logging Exceptions

Step 14 — Request Configuration Evidence

Section titled “Step 14 — Request Configuration Evidence”

Request:

CSPM Report
Public Resource Report
Encryption Coverage
Security Baseline Report
Network Exposure Report

Request:

ISO Certificates
SOC Reports
Provider Responsibility Documentation
Incident Terms
Subprocessor Lists

Request:

Backup Reports
Recovery Test Reports
DR Test Reports
Backup Exceptions

Review:

Physical Security
IAM
Logging
Encryption
Backup
Incident Response
Data Residency

For each control confirm:

Provider
Customer
Shared
Inherited
Control Responsibility
Physical Security Inherited
Privileged MFA Shared
Logging Shared
Guest OS Patching Customer
Backup Shared
Provider Incident Response Shared
Data Region Selection Shared

Verify every shared control has an internal owner.

Expected gap:

SaaS Data Deletion
→ No clear internal owner

Document as governance weakness.

09-Provider-Assurance-Assessment.md

Review five critical providers.

Use:

Provider Service Evidence Age Scope Status

Assume:

Provider A
→ Current ISO certificate
Provider B
→ Current SOC 2
Provider C
→ SOC 2 is 18 months old
Provider D
→ Current ISO 27001
Provider E
→ No recent assurance report

Use:

Current
Approaching Expiry
Stale
Unavailable

Result:

Provider C
→ Stale
Provider E
→ Unavailable

For Provider C:

Report covers:
Core SaaS Platform
Does not cover:
New AI Analytics Feature

Document:

Current assurance does not cover a newly enabled service feature processing customer data.

Requirement:

Critical cloud providers must have current risk-appropriate assurance evidence.

Condition:

Two of five critical providers do not have current complete assurance evidence.

Risk:

Provider control weaknesses
may remain unidentified.
05-Cloud-IAM-Assessment.md

Assume:

Privileged Human Identities:
64

MFA enabled:

61

MFA coverage:

95.3%

Expected:

100%

Step 28 — Investigate the Three Failures

Section titled “Step 28 — Investigate the Three Failures”

Find:

User 1
→ Emergency administrator
User 2
→ Legacy local account
User 3
→ SaaS super administrator

Emergency account:

Approved:
Yes
Strong credential:
Yes
MFA:
Not enabled
Compensating monitoring:
Yes

The enterprise control still requires strong authentication.

Status:

Exception Required

No approved exception exists.

Finding:

Local cloud administrator
bypasses federation and MFA.

Risk:

Credential compromise

Step 31 — Evaluate SaaS Super Administrator

Section titled “Step 31 — Evaluate SaaS Super Administrator”

Provider supports MFA.

Customer has not enabled it.

This is a clear shared-responsibility failure.

Write:

The Privileged Access Standard requires MFA for all privileged human cloud accounts. Three of sixty-four privileged accounts did not meet the requirement, including one legacy cloud administrator and one SaaS super administrator. No approved exceptions were recorded.

Requirement:

Quarterly privileged access review

Evidence:

Q1:
Complete
Q2:
Complete
Q3:
Missing for Azure
Q4:
Not Yet Due

Conclusion:

Partially Effective

Population:

142 workload identities

Find:

14 use long-lived static credentials
5 credentials older than 365 days
2 have administrator-equivalent access

Enterprise standard:

Managed or short-lived workload identities must be used where supported, and workload privileges must follow least privilege.

Conclusion:

Partially Implemented

Risk:

Static credential compromise
Excessive machine privilege

Recommended treatment:

Replace static credentials
Use managed identities / roles
Reduce permissions
Establish credential-age monitoring
06-Cloud-Logging-Assessment.md

Population:

15 IaaS / PaaS production environments

Forwarding to SIEM:

13

Coverage:

86.7%

Find:

AWS Account 7
→ Audit logs enabled locally
→ Not forwarded to SIEM
GCP Project 3
→ Audit logs partially enabled

Requirement:

365 days

Actual:

AWS:
365
Azure:
365
GCP:
90 days

Finding:

GCP retention below standard

Write:

Central administrative logging is incomplete. Two production environments are not fully integrated with the enterprise SIEM, and one GCP environment retains required audit logs for only 90 days rather than the 365-day standard.

Select three events:

New Admin Role
Logging Disabled
Public Storage Change

Results:

Admin Role
→ Alert configured
Logging Disabled
→ Alert configured
Public Storage Change
→ No detection rule

Document detection gap.

04-Cloud-Configuration-Assessment.md

Assess the fictional population:

Storage Resources:
120
Databases:
35
Compute Workloads:
75
Production Networks:
15

Requirement:

Production storage must not permit unauthorized public access.

Find:

120 Resources
Public:
3

Review:

Resource 1
→ Approved public website asset
Resource 2
→ No exception
Resource 3
→ No exception

Result:

2 unauthorized public resources

Requirement:

No unrestricted management ports

Find:

2 security groups
allow SSH from 0.0.0.0/0

No approved exceptions.

Population:

75 compute workloads

Compliant:

68

Noncompliant:

7

Gaps include:

Missing endpoint agent
Outdated image
Weak host firewall

Population:

155 storage and database resources

Encrypted:

153

Unencrypted:

2

Both unencrypted resources contain:

Internal-only test data

but baseline requires encryption for all cloud storage.

Conclusion:

Control Failure

Severity:

Medium

for this lab.

Customer-managed keys:

18

Find:

3 keys allow broad administrative access

Risk:

Unauthorized key use
07-Cloud-Data-Residency-Assessment.md

Population:

25 Restricted datasets

Approved region:

EU

Find:

23
→ EU
1
→ US analytics copy
1
→ Singapore backup

US analytics copy:

Approved transfer:
Yes
Current:
Yes

Singapore backup:

Approved:
No

Write:

One backup containing Restricted customer data is stored in a region not listed in the Approved Cloud Region Register and has no approved residency exception.

HR SaaS:

Primary:
EU
Provider support:
Global

Contract review shows support access is controlled but not restricted to EU.

Document as:

Risk Review Required

not automatically a control failure.

08-Cloud-Backup-Recovery-Assessment.md

Critical workloads:

20

Backup configured:

20

Coverage:

100%

Requirement:

Quarterly

Evidence:

16 workloads
→ Current recovery test
4 workloads
→ No test in last 12 months

Backups exist.

But:

Recoverability
→ Not demonstrated for 4 workloads

Finding:

Four critical workloads have not undergone required recovery testing within the established testing period.

Step 59 — Review Backup Failure Monitoring

Section titled “Step 59 — Review Backup Failure Monitoring”

Find:

Failure alerts:
Configured for 18/20 workloads

Two workloads rely on manual review.

Document improvement opportunity or finding based on lab assessment.

10-SaaS-Compliance-Assessment.md

Assess:

HR SaaS
CRM SaaS
Support SaaS

Findings:

MFA:
Not mandatory for 1 super admin
External sharing:
Not applicable
Retention:
Configured
Provider assurance:
Current

Findings:

MFA:
100%
External sharing:
12 guest users
4 guest accounts inactive > 180 days
Audit logs:
Enabled

Potential finding:

Dormant guest accounts

Findings:

Provider assurance:
Stale
Logs:
Available but not exported to SIEM
Customer PII:
Yes

This creates combined vendor and monitoring risk.

Find:

CRM
→ 18 OAuth integrations

Three have:

Unknown owner

Document:

Three active third-party SaaS integrations do not have documented business or technical owners.

Part 14 — Build the Control Testing Worksheet

Section titled “Part 14 — Build the Control Testing Worksheet”
03-Cloud-Control-Testing-Worksheet.md

Use:

Control Requirement Population Test Result Conclusion
Control Population Result
Privileged MFA 64 61 Pass / 3 Fail
SIEM Logging 15 13 Pass / 2 Fail
Encryption 155 153 Pass / 2 Fail
Approved Region 25 24 Pass / 1 Fail
Backup Recovery 20 16 Pass / 4 Fail

Use:

Effective
Partially Effective
Ineffective
Not Tested
11-Cloud-Audit-Findings-Register.md

Use:

ID Finding Control Risk Severity Owner Status
F-001
Cloud Inventory Incomplete

Severity:

High
F-002
Privileged MFA Gaps

Severity:

High
F-003
Incomplete Central Logging

Severity:

High
F-004
Unauthorized Public Cloud Resources

Severity:

High
F-005
Restricted Backup in Unauthorized Region

Severity:

High
F-006
Recovery Testing Overdue

Severity:

High
F-007
Stale Provider Assurance

Severity:

Medium / High
F-008
Long-Lived Workload Credentials

Severity:

Medium
12-Cloud-Risk-Impact-Analysis.md

Use:

Finding Related Risk Current Risk Impact
F-002
Privileged MFA Gap

Risk:

Cloud administrator compromise

Current rating:

High

Impact:

Unauthorized administrative access
F-003

Risk:

Security events remain undetected

Residual rating:

High
F-005

Risk:

Contractual / privacy violation

Residual rating:

High

Problem:

Undocumented cloud environments

Why?

Business teams can purchase cloud services directly.

Why?

Procurement process does not require cloud-security approval.

Root cause:

Cloud-service procurement is not consistently integrated with the formal cloud onboarding process.

Problem:

Privileged users without MFA

Root cause:

Legacy and SaaS administrator accounts are not included in the centralized privileged-identity control process.

Problem:

New accounts missing SIEM integration

Root cause:

Account provisioning does not automatically deploy centralized logging.

Problem:

Resources publicly accessible

Root cause:

Public-access prevention is detective rather than preventive.

Problem:

Backup deployed in unauthorized region

Root cause:

Backup configuration is not validated against approved residency requirements.

Problem:

Tests overdue

Root cause:

Recovery-test scheduling is manually maintained and lacks escalation.

13-Cloud-Remediation-Tracker.md

Use:

Finding Correction Corrective Action Owner Target Retest

Correction:

Add missing services to inventory.

Corrective action:

Require procurement and SSO integration workflows to trigger cloud-security onboarding review.

Correction:

Enable MFA on three privileged accounts.

Corrective action:

Extend enterprise privileged-identity monitoring to local and SaaS administrator accounts.

Correction:

Connect missing environments to SIEM.

Corrective action:

Automate centralized logging as part of account/project/subscription provisioning.

Correction:

Remove unauthorized public access.

Corrective action:

Implement preventive policy-as-code controls blocking unapproved public storage.

Correction:

Move backup to approved region.

Corrective action:

Add residency validation to backup policy and deployment controls.

Correction:

Perform recovery tests.

Corrective action:

Implement centralized recovery-test scheduling, reminders, escalation, and reporting.

Correction:

Obtain current provider assurance.

Corrective action:

Implement provider-assurance freshness monitoring and escalation.

A finding should not close simply because:

Owner says fixed.

Verify:

Correction
Corrective Action
Full Population
Latest Evidence
Recurrence Prevention

Expected:

64 / 64 privileged users
with approved MFA

Expected:

15 / 15 production environments
connected to SIEM

Also verify:

new account provisioning
automatically enables logging

Expected:

0 unauthorized public resources

and:

policy-as-code enforcement active

Expected:

25 / 25 Restricted datasets
in approved regions
or covered by approved exception

Expected:

20 / 20 critical workloads
with current recovery tests

After assessment, assign statuses.

Example:

Control Status
Cloud Inventory Partially Effective
Privileged MFA Partially Effective
Logging Partially Effective
Encryption Effective with Minor Gap
Data Residency Partially Effective
Backup Configuration Effective
Recovery Testing Partially Effective
Provider Assurance Partially Effective

Part 21 — Update Risk and Compliance Artifacts

Section titled “Part 21 — Update Risk and Compliance Artifacts”

Where relevant:

Finding
Risk Rating
Treatment Plan

If the assessment reveals ambiguity:

Clarify Provider Activity
Clarify Customer Activity
Assign Internal Owner

Where cloud control status changed:

Implemented
Partially Implemented

if appropriate.

Any accepted deviation must include:

Risk
Owner
Approver
Compensating Control
Expiry
14-Executive-Cloud-Compliance-Summary.md

Use:

Overall Cloud Compliance Status:
Partially Effective
Metric Result
Cloud Environments Identified 20
Inventory Coverage 90%
Privileged MFA Coverage 95.3%
SIEM Coverage 86.7%
Encryption Coverage 98.7%
Approved Residency Coverage 96%
Recovery Testing Coverage 80%
High Findings 6
Medium Findings 2

Highlight:

Privileged Access
Logging Gaps
Unauthorized Public Exposure
Data Residency
Recovery Readiness
Provider Assurance

Use:

CloudNova has established a strong cloud governance and shared-responsibility foundation, but the assessment identified material operational gaps in inventory completeness, privileged authentication, centralized logging, public exposure prevention, data residency, recovery testing, and provider assurance. Priority remediation should focus on converting manual controls into standardized and automated cloud guardrails.

Recommend:

Priority 1
→ Privileged MFA
Priority 2
→ Centralized Logging
Priority 3
→ Public Exposure Prevention
Priority 4
→ Residency Enforcement
Priority 5
→ Recovery Testing
Priority 6
→ Provider Assurance Automation

Before closing, ask:

Did we validate the full cloud inventory?
Did we understand shared responsibility?
Did we review provider evidence?
Did we test customer controls?
Did we test complete populations where possible?
Did we review SaaS?
Did we review residency?
Did we test recovery?
Did we identify root causes?
Did we define sustainable corrective actions?
Can findings be independently retested?

Your completed folder should contain:

Cloud-Compliance-Lab02/
├── 01-Cloud-Compliance-Assessment-Plan.md
├── 02-Cloud-Evidence-Request-List.md
├── 03-Cloud-Control-Testing-Worksheet.md
├── 04-Cloud-Configuration-Assessment.md
├── 05-Cloud-IAM-Assessment.md
├── 06-Cloud-Logging-Assessment.md
├── 07-Cloud-Data-Residency-Assessment.md
├── 08-Cloud-Backup-Recovery-Assessment.md
├── 09-Provider-Assurance-Assessment.md
├── 10-SaaS-Compliance-Assessment.md
├── 11-Cloud-Audit-Findings-Register.md
├── 12-Cloud-Risk-Impact-Analysis.md
├── 13-Cloud-Remediation-Tracker.md
└── 14-Executive-Cloud-Compliance-Summary.md
  • Assessment objective defined.

  • Cloud platforms scoped.

  • SaaS included.

  • Control domains identified.

  • Criteria defined.

  • Inventory validated.

  • Unknown environments identified.

  • Owners validated.

  • Data classifications reviewed.

  • Critical providers identified.

  • Assurance evidence collected.

  • Evidence freshness reviewed.

  • Scope validated.

  • Provider exceptions reviewed.

  • Privileged population identified.

  • MFA tested.

  • Federation reviewed.

  • Access reviews tested.

  • Workload identities assessed.

  • Static credentials reviewed.

  • Logging coverage measured.

  • SIEM integration reviewed.

  • Retention reviewed.

  • Detection coverage tested.

  • Log protection considered.

  • Public storage assessed.

  • Management ports assessed.

  • Compute baseline assessed.

  • Network exposure reviewed.

  • Policy-as-code reviewed.

  • Encryption coverage tested.

  • Key access reviewed.

  • Exceptions identified.

  • Restricted datasets identified.

  • Primary regions reviewed.

  • Backups reviewed.

  • Transfers reviewed.

  • SaaS support locations considered.

  • Backup coverage assessed.

  • Recovery testing assessed.

  • Failure monitoring reviewed.

  • MFA assessed.

  • Guest users reviewed.

  • External sharing reviewed.

  • Integrations reviewed.

  • Provider assurance reviewed.

  • Requirements identified.

  • Conditions documented.

  • Evidence recorded.

  • Risks described.

  • Severity assigned.

  • Owners assigned.

  • Corrections defined.

  • Root causes identified.

  • Corrective actions defined.

  • Targets assigned.

  • Retest evidence defined.

By completing this lab, you practiced:

Cloud Audit Planning
Cloud Inventory Validation
Provider Assurance Review
Shared Responsibility Testing
IAM Assessment
Privileged Access Testing
Workload Identity Assessment
Cloud Logging Assessment
Configuration Assessment
Encryption Assessment
Residency Assessment
Recovery Assessment
SaaS Compliance Assessment
Audit Evidence Analysis
Finding Writing
Root Cause Analysis
Risk Impact Analysis
Remediation Planning
Cloud Retesting
Executive Reporting

These are practical skills used by:

  • Cloud GRC Analysts.

  • Cloud Compliance Analysts.

  • Security Assurance Analysts.

  • Internal Auditors.

  • ISO Cloud Security Consultants.

  • Cloud Security Governance Analysts.

  • Third-Party Risk Analysts.

Package your work as:

CloudNova Technologies
Multi-Cloud Compliance Assessment

Include:

Executive Summary
Assessment Scope
Cloud Inventory
Provider Assurance Review
IAM Assessment
Logging Assessment
Configuration Assessment
Data Residency Assessment
Backup & Recovery Assessment
SaaS Assessment
Findings Register
Risk Impact Analysis
Remediation Plan

Do not use confidential information from a real employer or customer in a public portfolio.

You have now moved from:

Cloud Responsibility Defined

to:

Cloud Responsibility Tested
Evidence Validated
Gaps Identified
Risk Assessed
Root Cause Identified
Remediation Planned
Retest Defined

This is the complete operational lifecycle of a practical cloud compliance assessment.

➡️ Next: Runbook 01 — Cloud Compliance Assessment & Evidence Collection

In the next activity, you will turn the assessment methodology into a repeatable enterprise runbook covering:

Assessment Trigger
Scope Definition
Cloud Inventory Validation
Provider Assurance Collection
Shared Responsibility Review
Evidence Request
Control Testing
Finding Management
Risk Update
Remediation
Retesting
Management Reporting

The runbook will give GRC and cloud compliance teams a reusable procedure for performing periodic and event-driven cloud compliance assessments across IaaS, PaaS, SaaS, and multi-cloud environments.