Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “managed”

47 publications
Technical guideSource-based analysis

Protect and recover your AWS root account

Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Choose and verify CloudWatch Logs retention

Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep an S3 bucket private with Block Public Access

Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Remove public SSH access from an EC2 security group

Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Remove a document from an Amazon Bedrock knowledge base

Retire an S3 document from a Bedrock knowledge base through source changes, sync results, retrieval checks, and review of older application copies.

AI systems · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Google Cloud teams access through IAM groups

Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Require authentication between Cloud Run services

Configure Cloud Run service-to-service authentication with a dedicated caller identity, the right ID token audience, and useful negative tests.

Workload security · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Call Vertex AI from Cloud Run without a service account key

Use a Cloud Run service account and ADC to call Vertex AI, separate deployment and runtime permissions, and remove an obsolete prototype key.

AI systems · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Set up Cloud SQL backups and prove you can restore

Configure Cloud SQL PostgreSQL backups, understand retention settings, and rehearse a restore through database validation and application cutover.

Resilience · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Azure readers access to one resource group

Assign Reader without granting write access or assuming it grants data access.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Read an Azure Key Vault secret from a VM without a password

Set up one system-assigned VM identity and a vault-scoped secret permission.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Check and stop anonymous access to Azure blobs

Understand account and container settings and prove both anonymous denial and intended app access.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Restrict SSH and RDP access with an Azure network security group

Inspect effective rules, preserve the approved management path and test a fresh connection.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Connect to Azure OpenAI without an API key

Prove Entra-based inference with a scoped runtime identity before disabling local authentication.

AI systems · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure Key Vault secret

Distinguish secret recovery from vault recovery and verify versioned application references.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Design application authorization before writing Cedar policies

Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.

Identity & access · AWS / Cedar · By Cloud Security Desk
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep Terraform plans and state inside the change boundary

Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.

Workload security · HashiCorp / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Make PostgreSQL point in time recovery reproducible

Build a version-aware recovery chain from protected base backups and WAL through timeline selection, isolated replay and application acceptance.

Resilience · PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Plan Kubernetes drains around the disruption budget

Review selector scope, current status, unhealthy Pod handling and replacement capacity before treating a blocked drain as a reason to bypass availability controls.

Resilience · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Diagnose NAT gateway port exhaustion before adding capacity

Match allocation errors to destination tuples and gateway mode before changing connection pools, addresses or routes.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Prove Identity Center permission changes reached every account

A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Workload security · Kubernetes · By Cloud Security Desk