Cloud Security Self-Assessment Tool

Score your AWS, Azure or GCP security posture across five domains. CIS and NIST control mapping, provider-specific fixes and a phased remediation roadmap.

Advertisement

Cloud Security Self-Assessment for AWS, Azure and GCP

This cloud security self-assessment scores your cloud posture across five domains, maps every answer to CIS Benchmark and NIST control references, and returns a prioritised remediation roadmap with effort estimates and provider-specific fix instructions. Pick AWS, Azure, Google Cloud, multi-cloud, or another provider, and the remediation guidance changes to name the actual services you would use.

It is built for cloud and platform engineers, security leads inheriting an environment, and MSPs baselining a client tenancy. Twenty questions take about fifteen minutes. Progress saves automatically for seven days, results export to PDF, and the assessment runs entirely in your browser with no account and no connection to your cloud environment.

The Five Domains

  • Identity and Access Management — MFA enforcement on privileged accounts, permission review cadence, least-privilege enforcement, and credential lifecycle.
  • Configuration Management — secure baselines, infrastructure as code, drift detection, and public exposure of storage and compute.
  • Logging and Monitoring — API activity logging (CloudTrail, Azure Activity Log, Cloud Audit Logs), log retention, centralisation, and alerting.
  • Data Protection — encryption at rest and in transit, key management, classification, and backup integrity.
  • Incident Response — cloud-specific playbooks, detection tooling, automated response, and tested recovery.

Four questions per domain, each with five answer options describing a recognisable state of practice rather than a yes/no.

How the Score Is Calculated

Each answer scores 0 to 4, corresponding to a maturity state: 0 none, 1 initial, 2 developing, 3 defined, 4 optimized. The overall score is a straightforward completion percentage:

Overall % = (sum of answer scores ÷ (4 × number answered)) × 100

Domain scores use the same formula over that domain’s questions. Every question carries equal weight in the score you see — the assessment does not weight identity above logging in the headline number, so read the five domain percentages alongside the total rather than relying on the total alone.

Percentages map to maturity levels at 90% and above optimized, 75% defined, 50% developing, 25% initial, below that none. Because unanswered questions are excluded from the denominator, a partial assessment still produces a meaningful percentage — but a partial assessment answered only where you are strong will flatter you.

A worked example

Suppose you answer all twenty questions and score: identity 3, 2, 3, 1; configuration 2, 2, 1, 2; logging 3, 3, 2, 2; data protection 3, 4, 2, 3; incident response 1, 1, 0, 2.

  • Identity: 9 of 16 = 56% → Developing.
  • Configuration: 7 of 16 = 44% → Initial.
  • Logging: 10 of 16 = 63% → Developing.
  • Data protection: 12 of 16 = 75% → Defined.
  • Incident response: 4 of 16 = 25% → Initial.
  • Overall: 42 of 80 = 53% → Developing.

The overall figure of 53% is the least useful number on that list. What it conceals is a 50-point spread between data protection at 75% and incident response at 25%. In practice that profile describes an organisation that has invested in encryption and key management — visible, auditable, easy to procure — and has not written a cloud incident playbook, which is invisible until the day it is needed. Read the spread, not the average.

Framework Mapping and Remediation

Every question carries CIS Benchmark and NIST control references, so a low score converts directly into a named control gap you can cite in an audit conversation. Answers of “none” or “initial” are surfaced as critical gaps, and each generates a remediation task carrying the problem, the fix, an effort rating, an impact rating, a timeline, and the frameworks affected.

Remediation guidance is provider-specific. A logging gap returns CloudTrail multi-region trail instructions on AWS, Azure Activity Log and Monitor configuration on Azure, and Cloud Audit Logs on Google Cloud, rather than generic advice to “enable logging”.

Tasks are grouped into phases. Quick wins are low-effort, high-impact items achievable in one to two weeks. Critical remediation covers high-severity gaps over four to eight weeks. Strategic improvements run eight to sixteen weeks. Effort estimates use a coarse scale — low is about a day, medium about a week, high about a month — which is honest about the precision available from a twenty-question self-assessment.

How to Use It

  1. Select your provider. This filters provider-specific questions and determines which remediation instructions you receive.
  2. Answer for your actual production environment. Not the standard you intend to reach, and not your best-configured account. If practice varies across accounts or subscriptions, answer for the weakest.
  3. Read the five domain scores first. The spread between them is where the work is.
  4. Start with quick wins. MFA enforcement and enabling API activity logging are typically low-effort and high-impact, and they unblock everything downstream.
  5. Use the framework references to connect gaps to audit obligations.
  6. Export the PDF and re-run after remediation to evidence the change.

Why Cloud Posture Deserves Its Own Assessment

Cloud misconfiguration is a distinct failure mode from traditional network security: the control plane is an API, a single permissive policy can expose an entire data estate, and the shared responsibility model leaves gaps that neither party assumes are theirs. Verizon’s 2025 Data Breach Investigations Report, based on over 22,000 incidents and 12,195 confirmed breaches, found third-party involvement in breaches doubled to 30% and exploitation of vulnerabilities behind 20% of breaches, up 34% year on year. IBM’s Cost of a Data Breach Report 2026, covering 602 breached organisations, put the global average breach cost at $4.99M and the US average at $11.5M.

This assessment is a self-reported baseline, not a scan. It cannot see your environment, it cannot detect drift, and it will faithfully reflect an over-optimistic answer. Treat it as a structured conversation with your own configuration — useful for finding out which questions you cannot answer.

Frequently Asked Questions

Does this connect to my cloud account?

No. It never touches your environment and requests no credentials. It is a self-assessment questionnaire that runs entirely in your browser, which is also its main limitation: it reflects what you believe is configured, not what is.

How long does it take?

About fifteen minutes for twenty questions. Progress saves automatically for seven days, so you can pause and resume, and you will be offered a resume prompt when you return.

What score should I be aiming for?

75% or above puts you at Defined, meaning standardised practices across the organisation, which is a reasonable target for most production environments. Below 50% indicates inconsistent controls with meaningful exposure. Chasing 90%+ matters mainly for regulated or high-value workloads.

Are the domains weighted?

Not in the score you see — all twenty questions contribute equally. That is why the five domain percentages are presented alongside the total. A strong average built on a 25% incident response domain is not a strong posture.

Does it cover multi-cloud?

Yes. Select multi-cloud and you receive provider-neutral questions with general remediation guidance. If one provider dominates your estate, assessing that provider specifically gives sharper remediation instructions.

How do the CIS and NIST mappings work?

Each question references the CIS Benchmark and NIST controls it evidences. A low score therefore produces a named control gap you can take into an audit or a SOC 2 readiness conversation directly.

Are the effort estimates reliable?

They are coarse planning figures — roughly a day, a week, or a month per task. Use them to sequence work and set expectations, not to staff a project plan.

What should I do after the assessment?

Fix the quick wins, then broaden the picture. Assess the whole programme with the cybersecurity maturity assessment, and test recovery readiness with the ransomware resilience assessment.

What Is Cloud Security Self-Assessment

A cloud security self-assessment evaluates an organization's security posture in cloud environments against established benchmarks and best practices. As organizations migrate workloads to AWS, Azure, GCP, and other cloud platforms, the shared responsibility model creates new security challenges — cloud providers secure the infrastructure, but customers are responsible for securing their configurations, data, identities, and applications.

Cloud misconfiguration is consistently cited as the top cause of cloud breaches. Overly permissive IAM policies, publicly exposed storage buckets, unencrypted data, and missing logging are not software vulnerabilities — they are configuration errors that self-assessment can identify before attackers do.

Cloud Security Assessment Areas

AreaKey QuestionsCommon Misconfigurations
Identity & AccessWho can access what? How are credentials managed?Overly permissive IAM policies, no MFA, long-lived access keys
Data ProtectionIs data encrypted at rest and in transit?Unencrypted S3 buckets, public blob storage, no KMS
Network SecurityAre networks segmented? What is exposed?Open security groups, public subnets, no WAF
Logging & MonitoringAre actions logged? Are alerts configured?CloudTrail disabled, no SIEM integration, no alerting
Compute SecurityAre instances hardened? Are patches current?Default configurations, missing patches, root access
ComplianceDo configurations meet regulatory requirements?Missing encryption, inadequate access controls, no audit trail

Common Use Cases

  • Security baseline establishment: Evaluate your current cloud security posture to identify gaps and establish a remediation roadmap
  • Compliance readiness: Assess cloud configurations against SOC 2, PCI DSS, HIPAA, or CIS Benchmark requirements before audit
  • Post-migration review: After migrating workloads to the cloud, verify that security controls are properly configured in the new environment
  • Periodic health check: Conduct quarterly self-assessments to detect configuration drift and newly introduced risks
  • Multi-cloud comparison: Assess security posture across multiple cloud providers to identify inconsistencies and standardize controls

Best Practices

  1. Use CIS Benchmarks — The Center for Internet Security publishes detailed configuration benchmarks for AWS, Azure, and GCP. Use them as your assessment baseline.
  2. Automate configuration scanning — Tools like AWS Security Hub, Azure Security Center, GCP Security Command Center, and third-party CSPM tools continuously scan for misconfigurations.
  3. Focus on IAM first — Identity and access management misconfigurations are the most common and most exploitable cloud security issues. Audit IAM policies, enforce least privilege, and require MFA.
  4. Enable logging everywhere — CloudTrail (AWS), Activity Log (Azure), and Audit Logs (GCP) must be enabled in all regions and all accounts. Without logs, you cannot detect or investigate incidents.
  5. Treat infrastructure as code — Manage cloud configurations through Terraform, CloudFormation, or Pulumi. IaC enables code review, version control, and automated compliance scanning of infrastructure changes.

Frequently Asked Questions

What is cloud security self-assessment?+

What is cloud security self-assessment?

Cloud security self-assessment is a systematic evaluation of your cloud infrastructure against industry benchmarks like CIS Controls, NIST Cybersecurity Framework, and Cloud Security Alliance guidelines.

It identifies security gaps in identity management, data protection, network configuration, and compliance.

The assessment provides actionable recommendations to strengthen your cloud security posture and meet regulatory requirements.

How should I interpret my assessment score?+

Scores are typically categorized:

0-40% Critical (immediate action required),

41-60% Developing (significant improvements needed),

61-80% Maturing (good foundation with gaps),

81-95% Advanced (strong posture with minor improvements),

96-100% Optimized (industry-leading).

Compare your score against industry benchmarks for your sector.

Focus on critical controls first, particularly identity management, encryption, and logging.

What are common cloud security assessment findings?+

Common findings include:

inadequate multi-factor authentication,

overly permissive IAM policies,

unencrypted data at rest,

missing logging and monitoring,

publicly exposed storage buckets,

lack of network segmentation,

weak password policies,

and insufficient backup testing.

Many organizations also have incomplete asset inventories and fail to implement least privilege access.

Addressing these foundational issues significantly reduces risk.

How does this align with NIST Cybersecurity Framework?+

The assessment maps directly to NIST CSF core functions:

Identify (asset management, risk assessment),

Protect (access control, data security),

Detect (monitoring, anomaly detection),

Respond (incident response planning),

and

Recover (backup and recovery).

Each question evaluates specific controls within these categories, providing a comprehensive view of your cloud security maturity across all framework pillars.

What is the Cloud Security Alliance (CSA) framework?+

What is the Cloud Security Alliance (CSA) framework?

CSA provides the Security Guidance for Critical Areas of Focus in Cloud Computing, covering 14 domains including governance, compliance, data security, and identity management.

The Cloud Controls Matrix (CCM) offers specific security controls mapped to industry standards.

Our assessment incorporates CSA best practices to ensure comprehensive evaluation aligned with cloud-specific security requirements.

How often should I conduct cloud security assessments?+

How often should I conduct cloud security assessments?

Conduct comprehensive assessments quarterly, with continuous monitoring in between.

Perform immediate reassessment after major infrastructure changes, security incidents, or before compliance audits.

Monthly reviews of high-risk areas like IAM and data exposure are recommended.

Regular assessment establishes baselines, tracks improvement over time, and ensures security keeps pace with evolving cloud environments.

What are CIS Cloud Benchmarks?+

What are CIS Cloud Benchmarks?

CIS benchmarks provide prescriptive security configuration guidelines for AWS, Azure, GCP, and other cloud platforms.

They cover identity and access management, logging and monitoring, networking, storage, and compute security.

Level 1 benchmarks are foundational controls suitable for all organizations, while Level 2 includes defense-in-depth measures for high-security environments.

Following CIS benchmarks ensures baseline security.

How do I implement assessment recommendations?+

How do I implement assessment recommendations?

Prioritize findings by risk level and business impact.

Start with critical issues like exposed resources and weak authentication.

Create remediation plans with specific timelines and ownership.

Use infrastructure-as-code to implement controls consistently.

Leverage cloud-native security tools like AWS Security Hub or Azure Security Center.

Document changes and retest to verify effectiveness.

Consider professional assistance for complex remediations.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.