Cloud Security — Index

Cloud Security — Index

BLUF: Begin with provider hierarchy, identity and responsibility boundaries, then run read-only, zero-cost validation in owned disposable environments. Every exercise requires explicit IDs, seeded resources, audit telemetry, benign proof, stop conditions, and cleanup.

Mandatory gate

Complete Cloud Testing Scope and Rules of Engagement and record:

Use Cloud Validation Catalog as the exercise contract.

Curriculum order

Stage Entry Exit result
Cloud foundations Clouds Shared responsibility, hierarchy, identity, data, network, cost, quotas, resilience, and logging are identified
Scope and telemetry Scoping Exact IDs and log sources match authorization before any test
Azure/Entra foundations 1.3.1 Learn Cloud/0.1.2 Azure/ Entra roles, Azure RBAC, management groups, subscriptions, resource groups and data-plane authorization are separated
AWS foundations 1.3.1 Learn Cloud/0.1.3 AWS/ Organizations, management account, OUs, accounts, IAM, Regions, VPC, IMDSv2, CloudTrail and data events are understood
Read-only validation Cloud Validation Catalog One seeded behavior or control per card with audit evidence
Gated labs 1.3.2 Attack Cloud/ Third-party lab/version is current, owned, bounded, sanitized, and reversible
Detection and reporting Provider identity, control-plane and data-plane logs Finding includes coverage gaps, cost, mitigation, evidence and cleanup
Archive Retired APIs, transcripts and historical tool output Clearly non-executable and excluded from the active path

Current publication holds

Mapping rules

Use ATT&CK only for an observed behavior. A public bucket, broad role, missing log, tool, API or provider service is not automatically a technique. Record “no direct ATT&CK mapping” for configuration reviews rather than forcing one.