Free tools Windows power users keep installed
One-click scans. No signup required.
A useful cloud security audit starts by defining exactly which accounts, workloads, data, and requirements are in scope. Then compare their observed settings with a versioned, appropriately tailored baseline; preserve evidence for each control; assign and verify fixes; and keep checking for configuration drift. A dashboard or automated “pass” is evidence to assess—not proof that every relevant system is secure or compliant.
What a cloud security configuration audit should establish
An audit should show whether the cloud resources within a defined boundary match security requirements that make sense for their services, data, and risk. It should also make gaps traceable: a reviewer should be able to identify what was checked, what was observed, which requirement applied, and what happened next.
Cloud security follows a shared-responsibility model. AWS states, “Security is a shared responsibility between AWS and you.” The division of duties varies by service and service model, and customer responsibilities are also shaped by data, business requirements, and applicable laws. A cloud provider’s assurance about its infrastructure does not establish that a customer’s identities, network rules, storage permissions, or logging are configured safely.
Use the audit to assess a defined scope and record findings. Do not treat it as a compliance certification unless the audit has been designed and performed to meet the relevant program’s requirements.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
1. Define the boundary and purpose
Write down what the audit is for
State whether the review supports an internal risk assessment, compliance preparation, a change review, or another specific objective. The purpose affects which requirements matter, what evidence must be retained, and how findings should be prioritized.
Inventory the environment
List the cloud tenants and the accounts, subscriptions, or projects within scope. Record relevant regions, critical workloads, and resource types, such as compute, storage, databases, identity services, and networking. Identify sensitive data and the systems that store, transmit, or process it. Where an inventory is incomplete, make that limitation visible rather than implying the unlisted environment was assessed.
Map responsibility to services
For each service or workload, identify which security tasks belong to the provider and which remain with your organization. Confirm who owns customer-side controls, including configuration, access, data, and monitoring. The allocation depends on the service model and context; do not assume one responsibility map applies to every resource.
2. Select and tailor a versioned baseline
Choose guidance that matches the resources
Select a provider-native recommendation, a service-specific benchmark, or a recognized checklist that covers the systems in scope. Record the baseline’s name, edition or version, publication or retrieval date, applicable services, and any changes made for your environment. A checklist is useful only when the auditor can tell which requirement was applied and why.
Rank #2
NIST Special Publication 800-70 Revision 5 describes security configuration checklists as a way to configure and verify systems, identify unauthorized changes, and produce evidence of security posture. NIST notes that using checklists can minimize attack surface, reduce vulnerabilities, lessen the impact of successful attacks, and identify changes that might otherwise go undetected.
Do not treat cloud baselines as interchangeable
Google Cloud organizes its recommended minimum platform guidance into Basic, Intermediate, and Advanced levels, advising organizations to apply it in a graduated way suited to their use cases. Its six domains are authentication and authorization, organization, infrastructure, data protection, network security, and monitoring, logging, and alerting. Google Cloud’s 2026 announcement says the checklist contains 60 controls vetted by its Office of the CISO and subject matter experts.
CIS publishes separate Azure benchmarks for Compute Services, Database Services, Foundations, and Storage Services. Select the benchmark relevant to the Azure resources being reviewed and confirm its listed version; a Foundations benchmark alone should not be assumed to cover every service-specific configuration.
3. Review the controls that matter to the scope
Use the selected baseline to assess settings in context. A recommended value is not automatically appropriate for every workload: document the requirement, how it applies, and any justified exception instead of applying a universal setting blindly.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Identity and privileged access
- Review administrative and privileged identities, authentication strength, access assignments, and approval practices.
- Check how privileged access is governed over time, including exceptions and emergency accounts.
- Review administrative access paths and whether they are limited and monitored as required by the chosen baseline.
Microsoft’s cloud security benchmark calls for a documented identity and privileged-access strategy, including strong authentication and periodic governance of exceptions.
Organization and governance
- Check the account, project, or subscription structure, security ownership, and separation of duties.
- Verify that required organizational policies and guardrails apply to the resources in scope, not just to a parent environment or a sample.
Organization resource management is one of the domains in Google Cloud’s recommended checklist.
Network security
- Review segmentation, permitted ingress and egress, internet exposure, and hybrid connections.
- Check network monitoring and whether current diagrams or architecture artifacts match the deployed environment.
Microsoft’s benchmark includes network segmentation and a network security strategy. The precise settings to verify depend on the services and network design under review.
Data protection
- Identify sensitive data locations and the paths by which data moves between systems.
- Check access restrictions, encryption, and key lifecycle controls against the selected baseline and business requirements.
- Review whether the sensitive-data footprint is known and minimized where feasible.
Microsoft recommends tracking and minimizing sensitive data and controlling data and access keys through their lifecycle.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #4
Logging, monitoring, and response
- Confirm that relevant control-plane and resource logs are collected for the systems in scope.
- Check retention against the scenarios the organization needs to support, such as threat detection, incident response, or compliance.
- Verify that logs are reviewed or trigger appropriate alerts and are available to the teams responsible for response.
Monitoring, logging, and alerting are among Google Cloud’s checklist domains. Microsoft recommends tying log capture and retention to detection, response, and compliance scenarios.
Configuration, vulnerabilities, and supporting controls
Compare resource settings with defined baselines, look for drift and unsupported or vulnerable components, and determine whether findings are assigned and addressed. Microsoft recommends baselines for different resource types and continuous measurement, audit, enforcement, and review.
Include backup and recovery, endpoint security, and DevOps controls when the workloads depend on them or the audit scope requires them. Microsoft’s benchmark includes backup protection and monitoring and recommends applying security controls through the DevOps lifecycle.
4. Capture evidence so each finding can be reproduced
Maintain a record for every control assessed. At minimum, include:
- The control identifier or requirement and the baseline name and version.
- The account, project, or subscription and the specific resources examined.
- The expected state and the observed configuration.
- When and how the observation was collected, plus the location of supporting evidence.
- A result such as pass, fail, not applicable, or not assessed, with a reason for exceptions or exclusions.
- The risk and business effect, accountable owner, target date, and verification result for any remediation.
Preserve raw exports and reports as security-sensitive information: they can reveal resource names, exposure, settings, and weaknesses. NIST’s checklist guidance supports the core purpose of documenting configuration verification, detecting unauthorized changes, and producing posture artifacts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Use assessment tools without mistaking output for coverage
Automated tools can make repeatable checks and evidence collection more practical, but their findings depend on what they cover and how they are configured. Before relying on results, compare provider and service coverage, benchmark mappings and versions, account and region coverage, permissions and other prerequisites, evidence export, exception handling, and remediation tracking.
| Option | What the cited guidance establishes | What to verify for an audit |
|---|---|---|
| AWS Security Hub CSPM | AWS describes continuous, account-level configuration and security checks against standards and best practices. | Most controls require AWS Config to be enabled and recording resources. Verify that prerequisite and confirm the relevant accounts and regions are covered. (AWS Security Hub CSPM guidance) |
| Prowler | AWS Prescriptive Guidance describes Prowler as an open-source command-line tool for assessing, auditing, and monitoring AWS accounts against best practices and security frameworks. | Confirm the assessment’s framework and version, permissions, account scope, evidence output, and resource coverage. (AWS Prescriptive Guidance) |
| Microsoft Defender for Cloud CSPM | Microsoft describes posture visibility and assessment across Azure, AWS, and Google Cloud against standards selected for those environments. | Confirm the selected standards, connected environments, covered resources, and evidence and exception workflows. (Microsoft Defender for Cloud CSPM guidance) |
These descriptions establish different provider coverage and assessment approaches, not that one option is sufficient for every audit. A tool’s “pass” result does not show that every relevant control was assessed, that all resources were included, or that the organization meets a legal or audit requirement.
6. Prioritize findings, remediate, and reassess
Set priorities and ownership
Rank findings using exposure, business criticality, data sensitivity, threat context, and the purpose of the baseline. Assign an accountable owner and target date to each action. For accepted risks, record the approver, rationale, compensating controls, and a review or expiry date so acceptance does not become an undocumented permanent exception.
Verify fixes with fresh evidence
After a change, recheck the affected settings and retain new evidence showing the result. Close a finding only when the verification demonstrates that the intended state was reached; a ticket marked complete is not itself evidence of a secure configuration.
Keep watch between formal audits
Schedule reassessments and monitor for changes that could reintroduce a gap. Microsoft recommends continuous measurement and regular security-posture reviews; Google Cloud recommends monitoring tools to audit continued compliance after implementing its baseline. The appropriate cadence depends on the environment, risk, and obligations, so set it deliberately rather than assuming one annual review is enough.
How to choose a baseline or assessment tool
Before adopting a checklist or tool, compare it with the actual environment and audit objective:
Quick Recap
- Coverage: Does it include the cloud provider, regions, and resource types in use?
- Guidance type: Is it provider-native, service-specific, or intended to work across clouds?
- Control mapping: Which framework and exact benchmark edition or version does it use?
- Assessment cadence: Is it a one-time snapshot, a scheduled check, or continuous monitoring?
- Evidence: Can findings be exported with enough context and history for review?
- Operational fit: What permissions, configuration prerequisites, setup, and ongoing effort are required?
- Risk fit: Can it be tailored to workload design and applicable legal or contractual requirements while preserving documented exceptions?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




