Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “reader”
60 publicationsProtect and recover your AWS root account
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Identity & access · AWS · By Cloud Security DeskRemove unused AWS access keys without breaking a job
Review IAM access-key usage, find job dependencies, deactivate safely, and verify final deletion without collecting or exposing secret credentials.
Identity & access · AWS · By Cloud Security DeskChoose and verify CloudWatch Logs retention
Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.
Detection & response · AWS · By Cloud Security DeskMake CloudWatch alarms handle missing data correctly
Choose how CloudWatch alarms treat missing data, understand evaluation surprises, test notifications, and preserve useful alarm evidence.
Detection & response · AWS · By Cloud Security DeskKeep an S3 bucket private with Block Public Access
Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.
Workload security · AWS · By Cloud Security DeskRemove public SSH access from an EC2 security group
Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.
Workload security · AWS · By Cloud Security DeskCount tokens before sending a prompt to Amazon Bedrock
Count a Bedrock prompt for the chosen model, check endpoint support, distinguish context and output limits, and verify usage without logging prompts.
AI systems · AWS · By Cloud Security DeskRemove a document from an Amazon Bedrock knowledge base
Retire an S3 document from a Bedrock knowledge base through source changes, sync results, retrieval checks, and review of older application copies.
AI systems · AWS · By Cloud Security DeskRecover a deleted file with S3 Versioning
Recover an S3 object by inspecting retained versions, downloading a known copy, or removing the right delete marker without deleting the recovery data.
Resilience · AWS · By Cloud Security DeskChoose an RDS recovery window you can actually restore
Choose RDS backup retention, inspect the real restorable interval, validate an isolated database restore, and record cleanup and recovery limits.
Resilience · AWS · By Cloud Security DeskGive Google Cloud teams access through IAM groups
Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.
Identity & access · Google Cloud · By Cloud Security DeskGet an alert when Google Cloud project access changes
Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.
Detection & response · Google Cloud · By Cloud Security DeskKeep a Google Cloud Storage bucket private
Use public access prevention and uniform bucket-level access for Cloud Storage, then test IAM readers, signed links, and application dependencies.
Workload security · Google Cloud · By Cloud Security DeskRemove unnecessary personal data before sending Vertex AI prompts
Reduce personal data in Vertex AI prompts with field selection, Sensitive Data Protection, deliberate transformations, and safe failure handling.
AI systems · Google Cloud · By Cloud Security DeskRecover deleted Google Cloud Storage objects with soft delete
Choose a Cloud Storage soft delete window, restore a specific object generation, validate its contents, and account for retention and cleanup.
Resilience · Google Cloud · By Cloud Security DeskGive Azure readers access to one resource group
Assign Reader without granting write access or assuming it grants data access.
Identity & access · Azure · By Cloud Security DeskRead an Azure Key Vault secret from a VM without a password
Set up one system-assigned VM identity and a vault-scoped secret permission.
Identity & access · Azure · By Cloud Security DeskGet an Azure alert when a role assignment changes
Detect successful RBAC changes and test alert delivery without expanding a production role.
Detection & response · Azure · By Cloud Security DeskFind why an Azure VM cannot reach a service
Use a specific source and destination with Network Watcher and separate network reachability from app health.
Detection & response · Azure · By Cloud Security DeskCheck and stop anonymous access to Azure blobs
Understand account and container settings and prove both anonymous denial and intended app access.
Workload security · Azure · By Cloud Security DeskRestrict SSH and RDP access with an Azure network security group
Inspect effective rules, preserve the approved management path and test a fresh connection.
Workload security · Azure · By Cloud Security DeskHandle Azure OpenAI rate limits without retry storms
Separate deployment quota, short request bursts and bounded client retry behavior.
AI systems · Azure · By Cloud Security DeskConnect to Azure OpenAI without an API key
Prove Entra-based inference with a scoped runtime identity before disabling local authentication.
AI systems · Azure · By Cloud Security DeskRecover a deleted Azure blob with soft delete
Choose the right recovery action for a blob, version or container and verify restored bytes.
Resilience · Azure · By Cloud Security Desk