Review Cobalt methodologies for a Cloud Configuration Review.
:::info A Cloud Configuration Review is a configuration assessment of your AWS, Azure or GCP cloud environment against established security standards, including CIS benchmarks. This assessment is focused on reviewing and evaluating potential vulnerabilities without engaging in active exploitation.
:::
We support Cloud Configuration Reviews for the following cloud environments:
Cobalt conducts a configuration review of your AWS, Azure, or GCP cloud environment against established security standards, including CIS benchmarks.
The goal of this assessment is to identify misconfigurations. We will outline the potential impact, and provide recommendations for remediation. Example findings include: overly permissive IAM policies, open security groups, and unencrypted storage buckets. This assessment is focused on reviewing and evaluating potential vulnerabilities without engaging in active exploitation.
For Cloud Configuration Reviews, our team follows these steps:
In general, the cloud providers that we work with no longer need to know before we perform our audit. However, each cloud provider may have their own procedure.
For more details on the relevant procedures and policies, visit Cloud Provider Authorization documentation.
Cloud providers may need to include IP addresses associated with pentester traffic in their allowlist. We’ll share these addresses when you create a Cloud Configuration Review.
Our pentesters need access to review your AWS configurations. You should prepare:
These are the required policy Amazon Resource Names (ARN):
arn:aws:iam::aws:policy/SecurityAudit
arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
If available, you should also include the architecture of your cloud environment.
An AWS Cloud Configuration Review will identify misconfigurations. This assessment is focused on reviewing and evaluating potential vulnerabilities without engaging in active exploitation.
Cloud Configuration Reviews meet the Security standards based on the Center for Internet Security (CIS) Benchmarks.
AWS CIS Benchmarks cover IAM, Storage, Logging, Monitoring, and Networking.
Specific services that can be covered as part of the AWS configuration review include:
Our pentesters need access to review your GCP configurations. You should prepare:
A GCP Cloud Configuration Review will identify misconfigurations. This assessment is focused on reviewing and evaluating potential vulnerabilities without engaging in active exploitation.
Cloud Configuration Reviews meet the Security standards based on the Center for Internet Security (CIS) Benchmarks.
GCP CIS Benchmarks address the following areas:
Our pentesters need access to review your Azure configurations. You should prepare:
An Azure Cloud Configuration Review will identify misconfigurations. This assessment is focused on reviewing and evaluating potential vulnerabilities without engaging in active exploitation.
Cloud Configuration Reviews meet the Security standards based on the Center for Internet Security (CIS) Benchmarks.
Azure CIS Benchmarks address the following areas: