Runbook 01 β Cloud Compliance Assessment & Evidence Collection
Runbook Information
Section titled βRunbook Informationβ| Item | Details |
|---|---|
| Runbook | 01 β Cloud Compliance Assessment & Evidence Collection |
| Module | Cloud Compliance & ISO Cloud Standards |
| Difficulty | Advanced |
| Primary Role | Cloud GRC Analyst / Cloud Compliance Analyst |
| Supporting Roles | Cloud Security, IAM, SOC, Platform Engineering, Privacy, Legal, Procurement, Internal Audit |
| Applicable Environments | IaaS, PaaS, SaaS, Multi-Cloud |
| Primary Standards | ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 |
| Primary Output | Cloud Compliance Assessment & Evidence Package |
| Runbook Type | Cloud Assurance / Control Testing |
Purpose
Section titled βPurposeβThis runbook provides a reusable procedure for performing periodic or event-driven cloud compliance assessments.
The process covers:
Assessment Trigger βScope Definition βCloud Inventory Validation βShared Responsibility Review βProvider Assurance Review βEvidence Collection βEvidence Validation βControl Testing βFinding Identification βRisk Impact βRoot Cause Analysis βRemediation βRetesting βManagement ReportingThe objective is to determine whether cloud controls are:
-
Appropriately designed.
-
Implemented.
-
Operating consistently.
-
Supported by reliable evidence.
-
Aligned with provider/customer responsibility.
-
Connected to enterprise risk.
-
Ready for internal or external assurance.
Runbook Success Outcome
Section titled βRunbook Success OutcomeβAt the end of the process, the assessment team should be able to answer:
What cloud environments are in scope?
Who owns them?
Which data do they process?
Which controls apply?
Who operates each control?
Which controls are inherited?
What provider evidence supports them?
What customer evidence exists?
Which controls failed?
What risk do those failures create?
Who will remediate them?
Were corrective actions independently validated?Assessment Triggers
Section titled βAssessment TriggersβRun this procedure when any of the following occurs:
Scheduled Cloud Compliance Review
ISO Internal Audit
Certification Readiness Review
Major Cloud Migration
New Critical Cloud Provider
Major Cloud Architecture Change
Security Incident
Regulatory / Contractual Change
Material Provider Change
High-Risk Cloud FindingPhase 1 β Initiate the Assessment
Section titled βPhase 1 β Initiate the AssessmentβStep 1 β Record the Assessment Trigger
Section titled βStep 1 β Record the Assessment TriggerβCreate an assessment record.
Include:
Assessment ID
Trigger
Requestor
Date
Lead Assessor
Target CompletionExample:
Assessment ID:CCA-2026-03
Trigger:Annual Cloud Compliance ReviewStep 2 β Define the Objective
Section titled βStep 2 β Define the ObjectiveβExample:
Determine whether in-scope cloud governance, security, privacy, and compliance controls are appropriately implemented and operating across production cloud environments.
Step 3 β Identify Stakeholders
Section titled βStep 3 β Identify StakeholdersβTypical participants include:
GRC
Cloud Engineering
Cloud Security
IAM
SOC
Data Owners
Privacy
Legal
Procurement
Internal AuditStep 4 β Assign Assessment Lead
Section titled βStep 4 β Assign Assessment LeadβThe lead coordinates:
-
Scope.
-
Evidence requests.
-
Testing.
-
Findings.
-
Reporting.
-
Remediation tracking.
Phase 2 β Define Assessment Scope
Section titled βPhase 2 β Define Assessment ScopeβStep 5 β Identify In-Scope Providers
Section titled βStep 5 β Identify In-Scope ProvidersβDocument:
AWS
Azure
Google Cloud
Critical SaaS Providers
Private Cloudwhere applicable.
Step 6 β Identify In-Scope Cloud Objects
Section titled βStep 6 β Identify In-Scope Cloud ObjectsβInclude:
AWS Accounts
Azure Subscriptions
GCP Projects
SaaS Tenants
Cloud Regions
Production WorkloadsStep 7 β Identify In-Scope Services
Section titled βStep 7 β Identify In-Scope ServicesβExamples:
Compute
Object Storage
Managed Database
Identity
Logging
Kubernetes
Serverless
SaaS ApplicationsStep 8 β Identify In-Scope Data
Section titled βStep 8 β Identify In-Scope DataβDocument relevant classifications:
Public
Internal
Confidential
Restricted
PII
Payment DataStep 9 β Define Assessment Period
Section titled βStep 9 β Define Assessment PeriodβExample:
01 January 2026through30 June 2026Point-in-time evidence may not be sufficient for controls expected to operate throughout the period.
Step 10 β Define Criteria
Section titled βStep 10 β Define CriteriaβPossible criteria include:
ISO/IEC 27001
ISO/IEC 27017
ISO/IEC 27018
Cloud Security Policy
Cloud Configuration Standard
IAM Standard
Logging Standard
Data Residency Requirements
Backup & Recovery Standard
Provider ContractsPhase 3 β Validate Cloud Inventory
Section titled βPhase 3 β Validate Cloud InventoryβStep 11 β Obtain Approved Inventory
Section titled βStep 11 β Obtain Approved InventoryβRequest:
Cloud Account Inventory
SaaS Inventory
Provider Inventory
Application Inventory
Data InventoryStep 12 β Compare Against Discovery Sources
Section titled βStep 12 β Compare Against Discovery SourcesβUseful sources include:
Cloud Organizations
SSO Applications
Procurement
Expense Records
CSPM
CASB
DNS / Network DiscoveryStep 13 β Identify Inventory Differences
Section titled βStep 13 β Identify Inventory DifferencesβUse:
KnownUnknownDuplicateInactiveUnownedStep 14 β Validate Ownership
Section titled βStep 14 β Validate OwnershipβFor every environment confirm:
Business Owner
Technical Owner
Security OwnerStep 15 β Validate Criticality
Section titled βStep 15 β Validate CriticalityβConfirm classifications such as:
Critical
High
Moderate
LowStep 16 β Validate Data Classification
Section titled βStep 16 β Validate Data ClassificationβCheck whether system metadata aligns with actual data.
Step 17 β Record Inventory Gaps
Section titled βStep 17 β Record Inventory GapsβExample:
One active SaaS service processing customer information is absent from the approved Cloud Service Inventory.
Create a finding candidate if material.
Phase 4 β Review Shared Responsibility
Section titled βPhase 4 β Review Shared ResponsibilityβStep 18 β Obtain Responsibility Matrices
Section titled βStep 18 β Obtain Responsibility MatricesβRequest provider/customer responsibility documentation for critical services.
Step 19 β Classify Responsibility
Section titled βStep 19 β Classify ResponsibilityβUse:
Provider
Customer
Shared
InheritedStep 20 β Validate Service-Specific Responsibility
Section titled βStep 20 β Validate Service-Specific ResponsibilityβDo not assume responsibility is the same for every service from the same provider.
Example:
Virtual Machineβ Managed Databaseβ SaaSStep 21 β Identify Provider Activity
Section titled βStep 21 β Identify Provider ActivityβExample:
Control:Logging
Provider:Generates audit-event capabilityStep 22 β Identify Customer Activity
Section titled βStep 22 β Identify Customer ActivityβExample:
Customer:Enables loggingCentralizes logsDefines retentionMonitors eventsStep 23 β Validate Internal Ownership
Section titled βStep 23 β Validate Internal OwnershipβEvery customer and shared responsibility should have an internal owner.
Avoid:
Owner:Cloud Provider + CustomerInstead:
Internal Owner:SOC ManagerStep 24 β Identify Responsibility Gaps
Section titled βStep 24 β Identify Responsibility GapsβExample:
Provider provides backup capability
Customer assumes backup includes recovery testing
No recovery test existsDocument the gap.
Phase 5 β Review Provider Assurance
Section titled βPhase 5 β Review Provider AssuranceβStep 25 β Identify Critical Providers
Section titled βStep 25 β Identify Critical ProvidersβUse provider tiering or service criticality.
Step 26 β Request Provider Evidence
Section titled βStep 26 β Request Provider EvidenceβExamples:
ISO Certificates
SOC Reports
ISO/IEC 27017 Assurance
ISO/IEC 27018 Assurance
Security Documentation
Resilience InformationStep 27 β Validate Evidence Currency
Section titled βStep 27 β Validate Evidence CurrencyβUse:
Current
Approaching Expiry
Stale
UnavailableStep 28 β Validate Scope
Section titled βStep 28 β Validate ScopeβVerify:
Provider Entity
Service
Region
Period
Control ScopeStep 29 β Review Exceptions
Section titled βStep 29 β Review ExceptionsβInspect:
Audit Exceptions
Qualified Conclusions
Control Failures
Subservice OrganizationsStep 30 β Evaluate Customer Impact
Section titled βStep 30 β Evaluate Customer ImpactβFor each provider exception ask:
Does it affect our service?
Which inherited control?
Which risk?
Do we need treatment?Step 31 β Review Customer Responsibilities
Section titled βStep 31 β Review Customer ResponsibilitiesβProvider reports may state requirements such as:
Enable Logging
Manage Users
Review Access
Protect Credentials
Configure BackupsMap these to customer controls.
Phase 6 β Build the Evidence Request
Section titled βPhase 6 β Build the Evidence RequestβStep 32 β Create Evidence Request Tracker
Section titled βStep 32 β Create Evidence Request TrackerβUse:
| Request | Evidence | Owner | Due | Status |
|---|
Step 33 β Request Governance Evidence
Section titled βStep 33 β Request Governance EvidenceβExamples:
Cloud Inventory
Responsibility Matrix
Cloud Control Framework
Approved Region Register
Exception RegisterStep 34 β Request IAM Evidence
Section titled βStep 34 β Request IAM EvidenceβExamples:
Privileged User Inventory
MFA Coverage
Access Review Records
Service Account Inventory
Break-Glass AccountsStep 35 β Request Configuration Evidence
Section titled βStep 35 β Request Configuration EvidenceβExamples:
CSPM Reports
Cloud Policy Reports
Resource Inventory
Public Exposure Report
Security Baseline ReportStep 36 β Request Logging Evidence
Section titled βStep 36 β Request Logging EvidenceβExamples:
Log Source Inventory
SIEM Coverage
Retention Configuration
Detection Rules
Logging ExceptionsStep 37 β Request Data Protection Evidence
Section titled βStep 37 β Request Data Protection EvidenceβExamples:
Encryption Coverage
Key Permissions
Key Rotation
Data Classification
Region ConfigurationStep 38 β Request Resilience Evidence
Section titled βStep 38 β Request Resilience EvidenceβExamples:
Backup Status
Recovery Tests
DR Tests
Backup ExceptionsStep 39 β Request SaaS Evidence
Section titled βStep 39 β Request SaaS EvidenceβExamples:
Admin Users
MFA Status
External Users
Audit Logs
Integrations
Retention
Provider AssurancePhase 7 β Validate Evidence Quality
Section titled βPhase 7 β Validate Evidence QualityβStep 40 β Verify Evidence Relevance
Section titled βStep 40 β Verify Evidence RelevanceβAsk:
Does this evidence prove the control?Step 41 β Verify Scope
Section titled βStep 41 β Verify ScopeβCheck:
Correct accounts?
Correct systems?
Correct user population?Step 42 β Verify Period
Section titled βStep 42 β Verify PeriodβAsk:
Does it cover the assessment period?Step 43 β Verify Completeness
Section titled βStep 43 β Verify CompletenessβExample:
Production Accounts:50
Evidence:48
Result:IncompleteStep 44 β Verify Reliability
Section titled βStep 44 β Verify ReliabilityβPrefer evidence from authoritative systems.
Examples:
Cloud API
IAM Platform
SIEM
CSPM
GRC WorkflowStep 45 β Avoid Excessive Screenshot Reliance
Section titled βStep 45 β Avoid Excessive Screenshot RelianceβA screenshot may support one sample.
It does not normally prove a large population.
Step 46 β Record Evidence Metadata
Section titled βStep 46 β Record Evidence MetadataβInclude:
Evidence ID
Source
Date
Scope
Owner
ControlPhase 8 β Plan Control Testing
Section titled βPhase 8 β Plan Control TestingβStep 47 β Build the Control Testing Worksheet
Section titled βStep 47 β Build the Control Testing WorksheetβUse:
| Control | Requirement | Responsibility | Population | Test | Result |
|---|
Step 48 β Identify Population
Section titled βStep 48 β Identify PopulationβExamples:
64 Privileged Users
150 Storage Resources
20 Critical Workloads
15 Production AccountsStep 49 β Validate Population Completeness
Section titled βStep 49 β Validate Population CompletenessβAsk:
How was the population generated?
Does it cover all in-scope systems?
Can anything bypass it?Step 50 β Select Testing Method
Section titled βStep 50 β Select Testing MethodβUse:
Complete Population
Risk-Based Sampling
Random Sampling
Judgmental SamplingCloud APIs often make full-population testing practical.
Phase 9 β Test IAM Controls
Section titled βPhase 9 β Test IAM ControlsβStep 51 β Test Privileged MFA
Section titled βStep 51 β Test Privileged MFAβProcedure:
Identify privileged users βValidate MFA βIdentify failures βReview exceptionsPass condition:
100% privileged identitiesmeet approved authentication requirementStep 52 β Test Federation
Section titled βStep 52 β Test FederationβIdentify local accounts bypassing enterprise identity.
Step 53 β Test Privileged Role Assignments
Section titled βStep 53 β Test Privileged Role AssignmentsβAsk:
Approved?
Business need?
Least privilege?
Temporary where required?Step 54 β Test Access Reviews
Section titled βStep 54 β Test Access ReviewsβReview:
Population
Reviewer
Frequency
Decisions
Removal ActionsStep 55 β Test Break-Glass Accounts
Section titled βStep 55 β Test Break-Glass AccountsβVerify:
Restricted Use
Secure Credentials
Monitoring
Periodic TestingStep 56 β Test Workload Identities
Section titled βStep 56 β Test Workload IdentitiesβReview:
Service Accounts
Managed Identities
Static Keys
Credential Age
PrivilegePhase 10 β Test Logging & Monitoring
Section titled βPhase 10 β Test Logging & MonitoringβStep 57 β Define Required Log Sources
Section titled βStep 57 β Define Required Log SourcesβExamples:
Administrative Logs
Authentication Logs
Network Logs
Data Access LogsStep 58 β Measure Logging Coverage
Section titled βStep 58 β Measure Logging CoverageβExample:
Production Accounts:50
Integrated:48Record uncovered environments.
Step 59 β Validate Retention
Section titled βStep 59 β Validate RetentionβCompare actual retention with standard.
Step 60 β Validate Log Protection
Section titled βStep 60 β Validate Log ProtectionβAsk:
Who can delete logs?
Who can change retention?
Are changes logged?Step 61 β Test Detection
Section titled βStep 61 β Test DetectionβSample events:
New Administrator
Logging Disabled
Public Storage
Suspicious LoginTrace:
Eventβ Alertβ Investigationβ ClosurePhase 11 β Test Cloud Configuration
Section titled βPhase 11 β Test Cloud ConfigurationβStep 62 β Assess Public Exposure
Section titled βStep 62 β Assess Public ExposureβEvaluate:
Storage
Databases
Administrative Interfaces
Security Groups
SaaS SharingStep 63 β Review Approved Exceptions
Section titled βStep 63 β Review Approved ExceptionsβA public resource may be legitimate.
Confirm:
Business Need
Approval
Risk
ControlsStep 64 β Test Administrative Ports
Section titled βStep 64 β Test Administrative PortsβLook for:
SSH
RDP
Database Management
Administrative APIsopen to unrestricted sources.
Step 65 β Test Compute Baseline
Section titled βStep 65 β Test Compute BaselineβReview:
Approved Image
Patching
EDR
Host Firewall
LoggingStep 66 β Test Configuration Drift
Section titled βStep 66 β Test Configuration DriftβDetermine whether the organization detects changes from approved baseline.
Step 67 β Review Policy-as-Code
Section titled βStep 67 β Review Policy-as-CodeβAssess:
Coverage
Rules
Enforcement
Exceptions
Change ManagementPhase 12 β Test Encryption & Key Management
Section titled βPhase 12 β Test Encryption & Key ManagementβStep 68 β Identify Protected Population
Section titled βStep 68 β Identify Protected PopulationβExamples:
Databases
Object Storage
Disks
BackupsStep 69 β Validate Encryption
Section titled βStep 69 β Validate EncryptionβCompare against classification-based requirements.
Step 70 β Review Key Model
Section titled βStep 70 β Review Key ModelβIdentify:
Provider-Managed
Customer-Managed
Externally ManagedStep 71 β Test Key Access
Section titled βStep 71 β Test Key AccessβCheck:
Administrators
Applications
Key Usage
Logging
Access ReviewStep 72 β Identify Excessive Key Permissions
Section titled βStep 72 β Identify Excessive Key PermissionsβBroad key access can undermine encryption controls.
Phase 13 β Test Data Residency
Section titled βPhase 13 β Test Data ResidencyβStep 73 β Identify Restricted Datasets
Section titled βStep 73 β Identify Restricted DatasetsβUse:
Data Inventory
Classification RegisterStep 74 β Verify Primary Region
Section titled βStep 74 β Verify Primary RegionβCompare:
Actual RegionvsApproved RegionStep 75 β Verify Backups
Section titled βStep 75 β Verify BackupsβCheck backup and DR locations.
Step 76 β Review Processing Locations
Section titled βStep 76 β Review Processing LocationsβInclude:
Analytics
AI Services
Support Platforms
IntegrationsStep 77 β Review Cross-Border Transfers
Section titled βStep 77 β Review Cross-Border TransfersβCheck:
Approval
Purpose
Current Need
Security ControlsStep 78 β Review Subprocessors
Section titled βStep 78 β Review SubprocessorsβValidate relevant provider/subprocessor locations.
Step 79 β Review Support Access
Section titled βStep 79 β Review Support AccessβDetermine whether support-access locations are relevant to applicable requirements.
Phase 14 β Test Backup & Recovery
Section titled βPhase 14 β Test Backup & RecoveryβStep 80 β Validate Backup Coverage
Section titled βStep 80 β Validate Backup CoverageβFor every critical workload verify:
Backup Enabled
Frequency
Retention
EncryptionStep 81 β Review Backup Failures
Section titled βStep 81 β Review Backup FailuresβCheck whether failed jobs are detected and remediated.
Step 82 β Test Recovery Evidence
Section titled βStep 82 β Test Recovery EvidenceβRemember:
Backup Successβ RecoverabilityReview actual restore tests.
Step 83 β Compare Against Required Frequency
Section titled βStep 83 β Compare Against Required FrequencyβExample:
Required:Quarterly
Actual:No test in 12 monthsPotential finding.
Step 84 β Review Recovery Objectives
Section titled βStep 84 β Review Recovery ObjectivesβCompare actual results against:
RTO
RPOwhere defined.
Phase 15 β Assess SaaS
Section titled βPhase 15 β Assess SaaSβStep 85 β Identify Critical SaaS
Section titled βStep 85 β Identify Critical SaaSβInclude systems processing:
PII
Customer Data
Source Code
Identity
Financial DataStep 86 β Test SaaS Administrators
Section titled βStep 86 β Test SaaS AdministratorsβValidate:
Admin List
MFA
Ownership
Access ReviewStep 87 β Test Guest Users
Section titled βStep 87 β Test Guest UsersβReview inactive or unnecessary external accounts.
Step 88 β Test Sharing Controls
Section titled βStep 88 β Test Sharing ControlsβCheck:
Anonymous Links
External Sharing
Public ObjectsStep 89 β Test SaaS Integrations
Section titled βStep 89 β Test SaaS IntegrationsβInventory:
OAuth Applications
API Tokens
Connected AppsConfirm ownership and need.
Step 90 β Test SaaS Logging
Section titled βStep 90 β Test SaaS LoggingβDetermine whether audit logs are:
Available
Enabled
Exported
Retained
ReviewedStep 91 β Review SaaS Provider Assurance
Section titled βStep 91 β Review SaaS Provider AssuranceβApply the same provider-assurance procedure.
Phase 16 β Identify Findings
Section titled βPhase 16 β Identify FindingsβStep 92 β Establish Finding Criteria
Section titled βStep 92 β Establish Finding CriteriaβEvery finding should include:
Requirement
Condition
Evidence
RiskStep 93 β Write Specific Findings
Section titled βStep 93 β Write Specific FindingsβAvoid:
Cloud security is weak.
Prefer:
Three production cloud accounts were not forwarding required administrative audit logs to the enterprise SIEM during the assessment period.
Step 94 β Assign Severity
Section titled βStep 94 β Assign SeverityβUse approved methodology.
Possible levels:
Critical
High
Medium
LowStep 95 β Validate Findings With Owners
Section titled βStep 95 β Validate Findings With OwnersβConfirm factual accuracy.
Do not allow valid issues to disappear through wording negotiation.
Phase 17 β Assess Risk Impact
Section titled βPhase 17 β Assess Risk ImpactβStep 96 β Link Finding to Risk
Section titled βStep 96 β Link Finding to RiskβExample:
MFA Failure βPrivileged Account CompromiseStep 97 β Determine Existing Risk Record
Section titled βStep 97 β Determine Existing Risk RecordβIf a matching risk exists:
Update itIf not:
Create / Escalateaccording to risk methodology.
Step 98 β Review Residual Risk
Section titled βStep 98 β Review Residual RiskβControl failure may increase residual risk.
Step 99 β Identify Compliance Impact
Section titled βStep 99 β Identify Compliance ImpactβMap affected:
ISO Controls
ISO 27017 Guidance
ISO 27018 Controls
Customer Contracts
Internal StandardsPhase 18 β Perform Root Cause Analysis
Section titled βPhase 18 β Perform Root Cause AnalysisβStep 100 β Separate Correction From Root Cause
Section titled βStep 100 β Separate Correction From Root CauseβExample:
Issue:Logging missingCorrection:
Enable loggingRoot cause may be:
Account provisioningdoes not deploy logging baselineStep 101 β Use Five Whys Where Helpful
Section titled βStep 101 β Use Five Whys Where HelpfulβAsk:
Why did it happen?
Why was it not prevented?
Why was it not detected?Step 102 β Avoid Weak Root Causes
Section titled βStep 102 β Avoid Weak Root CausesβAvoid:
Human error
Forgot
Mistakeunless backed by deeper process analysis.
Phase 19 β Define Remediation
Section titled βPhase 19 β Define RemediationβStep 103 β Define Correction
Section titled βStep 103 β Define CorrectionβFix immediate condition.
Step 104 β Define Corrective Action
Section titled βStep 104 β Define Corrective ActionβAddress systemic cause.
Step 105 β Assign Owner
Section titled βStep 105 β Assign OwnerβUse a person/role with authority to remediate.
Step 106 β Define Target Date
Section titled βStep 106 β Define Target DateβBase on:
Severity
Risk
Dependencies
Implementation EffortStep 107 β Define Closure Evidence
Section titled βStep 107 β Define Closure EvidenceβExamples:
Configuration Export
Updated Workflow
Policy-as-Code Rule
Completed Recovery Test
Current Provider ReportPhase 20 β Track Remediation
Section titled βPhase 20 β Track RemediationβStep 108 β Maintain Remediation Tracker
Section titled βStep 108 β Maintain Remediation TrackerβUse:
| Finding | Action | Owner | Target | Status |
|---|
Step 109 β Use Standard Status
Section titled βStep 109 β Use Standard StatusβOpen
Planned
In Progress
Blocked
Ready for Retest
ClosedStep 110 β Escalate Overdue Findings
Section titled βStep 110 β Escalate Overdue FindingsβEscalation should be risk based.
Example:
High Finding βCISO / Risk OwnerPhase 21 β Retest Findings
Section titled βPhase 21 β Retest FindingsβStep 111 β Do Not Close on Attestation
Section titled βStep 111 β Do Not Close on AttestationβAvoid:
Owner says fixed βClosedStep 112 β Reperform Original Test
Section titled βStep 112 β Reperform Original TestβUse same or improved test procedure.
Step 113 β Validate Full Population Where Appropriate
Section titled βStep 113 β Validate Full Population Where AppropriateβExample:
Original:3 / 50 accounts missing logs
Retest:50 / 50 integratedStep 114 β Validate Root Cause Remediation
Section titled βStep 114 β Validate Root Cause RemediationβAlso test:
New account provisioningautomatically enables loggingStep 115 β Determine Retest Result
Section titled βStep 115 β Determine Retest ResultβUse:
Effective
Partially Effective
IneffectiveStep 116 β Close or Reopen
Section titled βStep 116 β Close or ReopenβPassβ Close
Failβ ReopenPhase 22 β Update Governance Artifacts
Section titled βPhase 22 β Update Governance ArtifactsβStep 117 β Update Cloud Inventory
Section titled βStep 117 β Update Cloud InventoryβAdd missing services and owners.
Step 118 β Update Responsibility Matrix
Section titled βStep 118 β Update Responsibility MatrixβClarify unclear responsibility.
Step 119 β Update Control Library
Section titled βStep 119 β Update Control LibraryβWhere control design changes.
Step 120 β Update SoA
Section titled βStep 120 β Update SoAβIf applicable control status changed.
Step 121 β Update Risk Register
Section titled βStep 121 β Update Risk RegisterβReflect changed residual risk.
Step 122 β Update Risk Treatment Plan
Section titled βStep 122 β Update Risk Treatment PlanβAdd remediation where needed.
Step 123 β Update Exception Register
Section titled βStep 123 β Update Exception RegisterβCapture accepted deviations.
Phase 23 β Build Management Reporting
Section titled βPhase 23 β Build Management ReportingβStep 124 β Prepare Executive Summary
Section titled βStep 124 β Prepare Executive SummaryβInclude:
Assessment Scope
Overall Control Status
High Findings
Top Cloud Risks
Provider Issues
Remediation PrioritiesStep 125 β Prepare Metrics
Section titled βStep 125 β Prepare MetricsβUseful examples:
Cloud Inventory Coverage
Privileged MFA Coverage
Logging Coverage
Encryption Coverage
Approved Region Coverage
Recovery Test Coverage
Current Provider AssuranceStep 126 β Highlight Trends
Section titled βStep 126 β Highlight TrendsβExample:
Logging Coverage:Q1 88%Q2 94%Q3 100%Trends are often more useful than one-time percentages.
Step 127 β Highlight Systemic Weaknesses
Section titled βStep 127 β Highlight Systemic WeaknessesβExamples:
Manual Account Provisioning
Fragmented IAM
Weak SaaS Governance
Incomplete Provider Assurance
Manual Recovery SchedulingPhase 24 β Continuous Evidence Collection
Section titled βPhase 24 β Continuous Evidence CollectionβStep 128 β Identify Automatable Evidence
Section titled βStep 128 β Identify Automatable EvidenceβExamples:
MFA
Logging
Encryption
Region
Public Exposure
Backup StatusStep 129 β Define Evidence Frequency
Section titled βStep 129 β Define Evidence FrequencyβExample:
Public Exposureβ Continuous
MFAβ Daily
Provider Assuranceβ AnnualStep 130 β Define Evidence Freshness
Section titled βStep 130 β Define Evidence FreshnessβDocument stale thresholds.
Step 131 β Integrate Cloud APIs
Section titled βStep 131 β Integrate Cloud APIsβWhere possible use:
Cloud API βEvidence Collector βEvidence RepositoryStep 132 β Monitor Evidence Pipelines
Section titled βStep 132 β Monitor Evidence PipelinesβTrack:
Collection Failures
Missing Accounts
Stale Evidence
API ErrorsPhase 25 β Evidence Packaging for Audit
Section titled βPhase 25 β Evidence Packaging for AuditβStep 133 β Build Evidence Index
Section titled βStep 133 β Build Evidence IndexβUse:
| Evidence ID | Control | Source | Period | Owner |
|---|
Step 134 β Remove Unnecessary Sensitive Data
Section titled βStep 134 β Remove Unnecessary Sensitive DataβDo not provide:
Passwords
Private Keys
Sensitive Customer Recordsunless strictly required and appropriately controlled.
Step 135 β Organize Evidence by Control
Section titled βStep 135 β Organize Evidence by ControlβExample:
IAM-002/βββ MFA-Coverageβββ Exception-Registerβββ RetestStep 136 β Maintain Traceability
Section titled βStep 136 β Maintain TraceabilityβAuditor should be able to follow:
Requirement βControl βEvidence βTest βFinding βRemediationCloud Compliance Assessment Checklist
Section titled βCloud Compliance Assessment ChecklistβInitiation
Section titled βInitiationβ-
Assessment trigger documented.
-
Objective defined.
-
Lead assigned.
-
Stakeholders identified.
-
Providers identified.
-
Accounts/subscriptions/projects identified.
-
SaaS included.
-
Data scoped.
-
Regions scoped.
-
Assessment period defined.
-
Criteria defined.
Inventory
Section titled βInventoryβ-
Inventory obtained.
-
Discovery comparison performed.
-
Unknown services identified.
-
Owners validated.
-
Data classifications reviewed.
Responsibility
Section titled βResponsibilityβ-
Responsibility matrices reviewed.
-
Provider controls identified.
-
Customer controls identified.
-
Shared controls identified.
-
Inherited controls identified.
-
Internal owners validated.
Provider Assurance
Section titled βProvider Assuranceβ-
Critical providers identified.
-
Current assurance collected.
-
Scope validated.
-
Exceptions reviewed.
-
Customer responsibilities mapped.
Evidence
Section titled βEvidenceβ-
Evidence request list issued.
-
Evidence sources validated.
-
Period validated.
-
Scope validated.
-
Completeness validated.
-
Evidence metadata recorded.
-
Privileged population validated.
-
MFA tested.
-
Federation tested.
-
Access reviews tested.
-
Break-glass accounts tested.
-
Workload identities tested.
Logging
Section titled βLoggingβ-
Required sources identified.
-
Coverage tested.
-
Retention validated.
-
Protection reviewed.
-
Detection tested.
Configuration
Section titled βConfigurationβ-
Public exposure tested.
-
Administrative ports tested.
-
Secure baseline tested.
-
Drift monitoring assessed.
-
Policy-as-code reviewed.
Data Protection
Section titled βData Protectionβ-
Encryption tested.
-
Key model reviewed.
-
Key access reviewed.
Residency
Section titled βResidencyβ-
Restricted datasets identified.
-
Primary locations validated.
-
Backup locations validated.
-
Transfers assessed.
-
Subprocessors considered.
-
Support access considered.
Recovery
Section titled βRecoveryβ-
Backup coverage tested.
-
Backup failures reviewed.
-
Recovery testing validated.
-
RTO/RPO considered.
-
SaaS admins tested.
-
MFA tested.
-
Guest users reviewed.
-
Sharing reviewed.
-
Integrations reviewed.
-
SaaS logging reviewed.
-
Provider assurance reviewed.
Findings
Section titled βFindingsβ-
Requirement identified.
-
Condition documented.
-
Evidence recorded.
-
Risk defined.
-
Severity assigned.
-
Owner assigned.
Remediation
Section titled βRemediationβ-
Correction defined.
-
Root cause identified.
-
Corrective action defined.
-
Target assigned.
-
Closure evidence defined.
-
Retest planned.
Closure
Section titled βClosureβ-
Retesting completed.
-
Findings closed or reopened.
-
Risk updated.
-
SoA updated where required.
-
Control library updated.
-
Management report issued.
Recommended Assessment Repository
Section titled βRecommended Assessment RepositoryβCloud-Compliance-Assessment/ββββ 01-Scope/β βββ Assessment-Planβ βββ Stakeholdersββββ 02-Inventory/β βββ Cloud-Inventoryβ βββ SaaS-Inventoryββββ 03-Responsibility/β βββ Shared-Responsibility-Matrixββββ 04-Provider-Assurance/β βββ Certificationsβ βββ SOC-Reportsβ βββ Provider-Reviewsββββ 05-Evidence/β βββ IAMβ βββ Loggingβ βββ Configurationβ βββ Encryptionβ βββ Residencyβ βββ Recoveryββββ 06-Testing/β βββ Control-Testing-Worksheetsββββ 07-Findings/β βββ Findings-Registerββββ 08-Remediation/β βββ Remediation-Trackerββββ 09-Retest/β βββ Retest-Evidenceββββ 10-Reporting/ βββ Executive-SummaryQuick Reference β Assessment Decision Tree
Section titled βQuick Reference β Assessment Decision TreeβCloud Environment In Scope? β βββ No β Document Exclusion β βββ Yes βInventory Complete? β βββ No β Raise Governance Gap β βββ Yes βResponsibility Defined? β βββ No β Clarify Provider/Customer Responsibility β βββ Yes βEvidence Available? β βββ No β Evidence Gap β βββ Yes βEvidence Complete & Current? β βββ No β Assurance Gap β βββ Yes βControl Operating? β βββ No β Finding β βββ Yes βEffective? β βββ No β Control Design Gap β βββ Yes β PassQuick Reference β Evidence Validation
Section titled βQuick Reference β Evidence ValidationβFor every evidence item ask:
Right Source?
Right Scope?
Right Period?
Complete Population?
Reliable?
Reproducible?
Current?
Protected?Quick Reference β Finding Structure
Section titled βQuick Reference β Finding StructureβUse:
[Requirement] requires [expected condition]. The assessment identified [actual condition] based on [evidence]. This may result in [risk/impact].
Example:
The Cloud Logging Standard requires centralized administrative logging for all production cloud accounts. The assessment identified two of fifteen production environments that were not fully forwarding administrative logs to the enterprise SIEM. This reduces CloudNovaβs ability to detect and investigate unauthorized administrative activity.
Common Runbook Failures
Section titled βCommon Runbook FailuresβFailure 1 β Starting With Evidence Requests Before Scope
Section titled βFailure 1 β Starting With Evidence Requests Before ScopeβTeams collect unnecessary information.
Failure 2 β Assuming Inventory Is Complete
Section titled βFailure 2 β Assuming Inventory Is CompleteβUnknown cloud services escape assessment.
Failure 3 β Ignoring Shared Responsibility
Section titled βFailure 3 β Ignoring Shared ResponsibilityβThe wrong party is asked for evidence.
Failure 4 β Provider Certificate Accepted Without Scope Review
Section titled βFailure 4 β Provider Certificate Accepted Without Scope ReviewβInherited controls may not actually be covered.
Failure 5 β Current Screenshot Used for Historical Control
Section titled βFailure 5 β Current Screenshot Used for Historical ControlβOperation throughout the assessment period is not demonstrated.
Failure 6 β Only IaaS Is Assessed
Section titled βFailure 6 β Only IaaS Is AssessedβSaaS risk remains unmanaged.
Failure 7 β Configuration Scanning Replaces Control Testing
Section titled βFailure 7 β Configuration Scanning Replaces Control TestingβGovernance and operating effectiveness are missed.
Failure 8 β Findings Have No Requirement
Section titled βFailure 8 β Findings Have No RequirementβThey become opinions rather than audit observations.
Failure 9 β Immediate Fix Equals Closure
Section titled βFailure 9 β Immediate Fix Equals ClosureβRoot cause remains.
Failure 10 β Assessment Does Not Update Risk
Section titled βFailure 10 β Assessment Does Not Update RiskβCompliance and enterprise risk remain disconnected.
Practical Cloud Assurance Mindset
Section titled βPractical Cloud Assurance MindsetβA weak assessment asks:
Is the checkbox green?
A stronger assessment asks:
Does the configuration meet the requirement?
A mature assessment asks:
Is the control well designed, operating across the complete population, supported by reliable evidence, aligned with shared responsibility, reducing the intended risk, and able to remain effective as the cloud environment changes?
That is the mindset required for meaningful cloud compliance assurance.
Runbook Deliverables
Section titled βRunbook DeliverablesβA completed assessment package should contain:
01 β Assessment Plan
02 β Validated Cloud Inventory
03 β Responsibility Matrix
04 β Provider Assurance Review
05 β Evidence Request Register
06 β Evidence Index
07 β IAM Assessment
08 β Logging Assessment
09 β Configuration Assessment
10 β Encryption Assessment
11 β Data Residency Assessment
12 β Backup & Recovery Assessment
13 β SaaS Assessment
14 β Control Testing Worksheets
15 β Findings Register
16 β Risk Impact Analysis
17 β Root Cause Records
18 β Remediation Tracker
19 β Retest Records
20 β Executive SummaryRunbook Completion Criteria
Section titled βRunbook Completion CriteriaβThe assessment is complete when:
Scope is documented
Cloud inventory is validated
Responsibilities are understood
Provider assurance is current
Evidence is complete
Critical controls are tested
Findings are documented
Risk impact is assessed
Root causes are identified
Corrective actions are assigned
Retesting is completed or scheduled
Management receives the assessment resultRunbook Complete
Section titled βRunbook CompleteβYou now have a repeatable enterprise workflow for moving from:
Cloud Environmentto:
Validated Inventory βResponsibility Mapping βEvidence βControl Testing βFindings βRisk βRemediation βRetesting βManagement AssuranceThis procedure can be reused for scheduled assessments, internal audits, ISO certification readiness, major cloud changes, provider reviews, and event-driven cloud compliance investigations.
Whatβs Next?
Section titled βWhatβs Next?ββ‘οΈ Next: Runbook 02 β Cloud Compliance Exception, Remediation & Continuous Monitoring
In the next and final runbook for this module, you will operationalize what happens after a cloud control fails or an exception is requested.
You will build the lifecycle:
Control Violation βDetermine Immediate Risk βCorrect Immediate Exposure βException or Remediation? βRisk Assessment βCompensating Controls βApproval βCorrective Action βContinuous Monitoring βRetest βClose / Renew / EscalateThe runbook will connect cloud exceptions, risk acceptance, remediation, policy-as-code, continuous control monitoring, evidence freshness, and management escalation into one repeatable operating process.