Back to Learning Centre
Checklist

Cloud Security Assessment Checklist

Assess the security of your cloud environment across AWS, Microsoft Azure, Google Cloud, and Huawei Cloud.

Synaptic Technologies · v1.0 · 2026

Migrating to the cloud introduces significant security benefits — but also new risks if not configured correctly. Misconfigured cloud environments are one of the leading causes of data breaches globally. Use this checklist to assess your cloud security posture and identify gaps before attackers do.

01

Identity & Access Management (IAM)

The root/master account is not used for day-to-day operations.
MFA is enforced on all cloud console accounts, especially privileged users.
The principle of least privilege is applied — users and services only have the permissions they need.
IAM roles are used for service-to-service access instead of long-lived access keys.
Access keys are rotated regularly (at least every 90 days).
Unused accounts and access keys are disabled or deleted.
IAM policies are reviewed quarterly.
02

Data Security & Encryption

All data at rest (databases, storage buckets, disks) is encrypted.
All data in transit is encrypted using TLS 1.2 or higher.
Encryption keys are managed using a dedicated key management service (KMS).
No storage buckets or containers are publicly accessible unless explicitly required.
Sensitive data (PII, financial records) is classified and subject to additional controls.
Data residency requirements are understood — data is stored in compliant regions.
03

Network Security

Virtual Private Cloud (VPC) / Virtual Network is configured with appropriate subnet segmentation.
Security groups and network ACLs follow the principle of least privilege (deny all, allow specific).
No security groups allow unrestricted inbound access (0.0.0.0/0) on sensitive ports (22, 3389, 1433, 3306).
A Web Application Firewall (WAF) is in place for internet-facing applications.
DDoS protection is enabled.
VPN or private connectivity is used for administrative access to cloud resources.
04

Logging, Monitoring & Alerting

Cloud audit logging (CloudTrail / Azure Monitor / Cloud Audit Logs) is enabled across all accounts and regions.
Logs are stored in a separate, tamper-resistant location.
Log retention meets compliance requirements (minimum 12 months recommended).
Alerts are configured for suspicious activity: root account usage, failed logins, privilege escalation.
A Security Information and Event Management (SIEM) solution or cloud-native security hub is in use.
Alerts are reviewed and actioned by a responsible person or team.
05

Vulnerability & Patch Management

Cloud-native vulnerability scanning is enabled (AWS Inspector, Microsoft Defender, etc.).
Operating systems and software on cloud instances are patched regularly.
Container images are scanned for vulnerabilities before deployment.
A process exists to remediate critical vulnerabilities within 72 hours.
End-of-life operating systems and software are not running in production.
06

Backup & Disaster Recovery

Automated backups are configured for all critical databases and storage.
Backups are stored in a separate region or account.
Backup restoration has been tested in the last 6 months.
A documented disaster recovery plan exists with defined RTO and RPO.
DR failover has been tested at least once in the last 12 months.
07

Compliance & Governance

Cloud security posture management (CSPM) tools are in use to detect misconfigurations.
A cloud security policy is documented and communicated to all relevant staff.
Third-party cloud service providers have been assessed for security compliance.
Data processing agreements are in place with cloud providers (POPIA requirement).
Cloud costs and resource usage are monitored to detect anomalies (potential cryptomining or abuse).

This checklist is provided for informational purposes by Synaptic Technologies. It does not replace a formal cloud security assessment. Contact us at [email protected] for a professional cloud security review.

Need a Cloud Security Review?

Our cloud security specialists can assess your environment and help you close critical gaps.

Contact Us