Cloud Security Configuration

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Implement comprehensive cloud security across AWS, Azure, and GCP with IAM, encryption, network security, compliance, and threat detection.

Includes scripts

Cloud Security Configuration

Table of Contents

Overview

Cloud security requires comprehensive strategies spanning identity management, encryption, network controls, compliance, and threat detection. Implement defense-in-depth with multiple layers of protection and continuous monitoring.

When to Use

  • Protecting sensitive data in cloud
  • Compliance with regulations (GDPR, HIPAA, PCI-DSS)
  • Implementing zero-trust security
  • Securing multi-cloud environments
  • Threat detection and response
  • Identity and access management
  • Network isolation and segmentation
  • Encryption and key management

Quick Start

Minimal working example:

bash
# Enable GuardDuty (threat detection)aws guardduty create-detector \  --enable \  --finding-publishing-frequency FIFTEEN_MINUTES
# Enable CloudTrail (audit logging)aws cloudtrail create-trail \  --name organization-trail \  --s3-bucket-name audit-bucket \  --is-multi-region-trail
# Enable S3 bucket encryption by defaultaws s3api put-bucket-encryption \  --bucket my-bucket \  --server-side-encryption-configuration '{    "Rules": [{      "ApplyServerSideEncryptionByDefault": {        "SSEAlgorithm": "aws:kms",        "KMSMasterKeyID": "arn:aws:kms:region:account:key/key-id"      },      "BucketKeyEnabled": true    }]  }'
# Enable VPC Flow Logs// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS Security Configuration [blocked]AWS Security Configuration
Terraform Security Configuration [blocked]Terraform Security Configuration
Azure Security Configuration [blocked]Azure Security Configuration
GCP Security Configuration [blocked]GCP Security Configuration

Best Practices

✅ DO

  • Implement least privilege access
  • Enable MFA everywhere
  • Use service accounts for applications
  • Encrypt data at rest and in transit
  • Enable comprehensive logging
  • Implement network segmentation
  • Use secrets management
  • Enable threat detection
  • Regular security assessments
  • Keep systems patched

❌ DON'T

  • Use root/default credentials
  • Store secrets in code
  • Over-permissive security groups
  • Disable encryption
  • Ignore logs and monitoring
  • Share credentials
  • Skip compliance requirements
  • Trust unverified data sources

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/cloud-security-configurationat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Cloud Security Configuration Agent Skill | SourceWeft