Cloud Security Checklist
Use this checklist to harden cloud environments across identity, network, data, and operations.
Identity and access
Enforce MFA, use centralized identity, apply least-privilege roles, and rotate secrets automatically. Review access weekly.
Network protection
Segment traffic, restrict public exposure, use private endpoints where possible, and inspect east-west traffic.
Data protection
Classify data, encrypt in transit and at rest, enable key rotation, and prevent data exfiltration with DLP controls.
Logging and detection
Centralize logs, enable anomaly detection, define alert thresholds, and test response playbooks monthly.
Incident response
Document escalation paths, maintain runbooks, assign ownership, and run tabletop exercises quarterly.