Standard Security Controls
Patches & Updates Change Defaults Firewall IPS/IDS SDLC Logging and Monitoring Anti-DOS Systems Encryption Endpoint Host Protection
Cloud-Specific Security Controls
IAM Policy
Bucket Enabling
Kubernettes Security Controls
Update Restrict API access Restrict SSH access Use namespaces Network policies Do not run as root IAM access Security reviews
Docker Security Controls
Update Do not expose daemon to container Set user Limit access No new privileges flag -icc false flag Selinux Read-only Static analysis tools Logging
Cloud Security Control Tools
Qualys Prisma cloud Aqua cloud Tenable Kube-bench Sumo Logic