Walk-Through – Assessing IAM Controls
From Chapter 1, Cloud Architecture and Navigation, to Chapter 6, Tips and Techniques for Advanced Auditing, we built foundational knowledge of cloud structure, navigation, and security controls, and in Chapter 7, Tools for Monitoring and Assessing, we learned about tools available for auditing. Now, it’s time to put our learning into practice by performing some example audit walk-throughs of basic controls within the major cloud providers.
In this chapter, we’ll cover the following main topics:
- Preparing to assess cloud IAM controls
- Assessing authentication and authorization
- Assessing access assignment controls
- Assessing privileged access controls
- Assessing device controls
We will pose an assessment question for each of the topic areas and execute a basic test procedure. By the end of this chapter, you will be able to perform a basic audit walk-through of a few IAM controls across the three...