
Cloud Security Posture Assessment
Assess cloud security posture, identify risks, and prioritize remediation across AWS, Azure, GCP
What You Can Do
This skill systematically evaluates your cloud infrastructure against industry security frameworks like CIS Benchmarks, NIST, and compliance standards, then identifies misconfigurations, vulnerabilities, and security gaps. You'll receive a prioritized remediation plan with risk scores, remediation steps, and compliance mappings to guide your security hardening efforts.
Features
Evaluate against CIS Benchmarks, NIST CSF, PCI-DSS, HIPAA, SOC2, and ISO27001
Identify weak IAM policies, exposed storage, unencrypted data, open security groups, and logging gaps
CVSS and custom risk metrics to focus effort on highest-impact findings
Step-by-step instructions with code examples for IaC (Terraform, CloudFormation, ARM)
Understand which findings block specific regulatory certifications
Quantify security spend vs. remediation complexity to optimize roadmap
Assess AWS, Azure, GCP, and hybrid environments in a single report
Executive summary, detailed findings, and technical playbooks in markdown
Example Output
Assessment Report Summary:
- ✅ Compliance Status:
- CIS Benchmarks: 68/112 controls (61%)
- NIST CSF: 71% implemented
- PCI-DSS: 3 critical gaps blocking certification
Critical Findings (Risk Score 9.2/10):
-
S3 bucket
prod-data-backupmissing encryption and public access block- Remediation: Apply bucket policy, enable SSE-KMS, block public ACLs
- Effort: 30 min | Cost: $15/month
-
IAM role
Lambda-Executionhas*:*permissions- Remediation: Scope to S3, CloudWatch Logs only
- Effort: 20 min | Cost: $0
Compliance Gap Example:
- Finding: VPC flow logs disabled on 4 subnets
- Blocks: SOC2 Type II audit (logging requirement)
- Fix: Enable flow logs to CloudWatch Logs
30-Day Roadmap:
- Week 1: Critical IAM and encryption (3 findings, 2h effort)
- Week 2: Logging and monitoring (5 findings, 4h effort)
- Week 3: Network hardening (2 findings, 1.5h effort)
- Week 4: Documentation and verification (1h effort)
What's Included
- SKILL.md: Core assessment skill with decision trees and validation rules
- Framework templates: CIS, NIST, PCI-DSS, HIPAA, SOC2, ISO27001 checklists
- Remediation playbooks: Step-by-step guides for 50+ common cloud security findings
- Risk scoring calculator: Custom weighting for your environment and risk tolerance
- IaC remediation snippets: Terraform and CloudFormation examples for each finding
- Compliance mapping worksheet: Cross-reference findings to regulatory requirements
- Report templates: Executive summary, detailed technical report, and action plan formats
- Evidence collection checklist: Verification steps for audits
Who It's For
- Cloud Security Engineers — Reduce assessment time from days to hours
- Cloud Architects — Validate designs against security frameworks before deployment
- Security Operations Centers (SOC) — Triage findings and guide remediation efforts
- Compliance Officers — Map technical findings to regulatory requirements
- DevOps/Infrastructure Teams — Shift-left security into CI/CD with automated posture checks
- CISO Offices — Get risk-quantified executive dashboards for budget decisions
Best For
- Initial cloud security baselines — Establish baseline compliance when migrating to cloud
- Pre-audit preparation — Get ahead of SOC2, ISO27001, HIPAA, or PCI-DSS audits
- Post-incident hardening — Systematic remediation after a security event
- Third-party security assessments — Provide evidence to customers or regulators
- Continuous compliance — Monthly or quarterly reassessments to track progress
- Budget justification — Quantify security spending with risk and compliance impact







