Information Security
Cloud Security Assessment Checklist
🔒

Cloud Security Assessment Checklist

1
Identify and document the cloud services being used
2
Perform risk assessment of the cloud services
3
Review the cloud service provider's security policies
4
Check encryption methods used for data transmission
5
Approval: Encryption Methods
6
Check data storage encryption
7
Investigate incident response time
8
Approval: Incident Response Time
9
Review cloud service provider's SLA
10
Verify compliance with relevant regulations and standards
11
Evaluate the security of APIs being used
12
Review user access management policies
13
Investigate existence of malware protection systems
14
Auditing of log and event data
15
Approval: Log Auditing
16
Test Disaster Recovery and Business Continuity Planning
17
Verify Secure Development Life Cycle (SDLC) processes
18
Check availability of multi-factor authentication
19
Approval: Multi-Factor Authentication
20
Assess vendor lock-in risks and exit strategies