Fundamentals of Cloud Security Practices
Technology Corrected & verified

Fundamentals of Cloud Security Practices

Published by When Notes Fly · View original ↗

Cloud security involves shared responsibilities to protect data and applications in cloud environments.

Page Summary

An introduction to cloud security fundamentals, opening with the 2019 Capital One breach caused by a misconfiguration rather than an AWS flaw. Built around the shared-responsibility model, it covers identity and access management as the highest-leverage control, network security architecture (VPCs, public/private subnets, security groups, secure administrative access), encryption at rest and in transit with key management, storage and database protection, secrets management, logging and threat detection, common vulnerabilities, compliance frameworks, and security-as-code automation.

Contributions

Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.

  1. 11 July 2026 · corrected by Melik Can Sariyer

    2 corrections applied: The Rhino Security Labs '21 ways to escalate privileges in AWS IAM' research was authored by Spencer Gietzen, not Scott Piper | Same attribution fix: the Rhino Security Labs IAM privilege-escalation research was by Spencer Gietzen, not Scott Piper

    Before

    Scott Piper's "AWS IAM Privilege Escalation" research; Piper's research, conducted at Rhino Security Labs

    After

    Spencer Gietzen's "AWS IAM Privilege Escalation" research; Gietzen's research, conducted at Rhino Security Labs

    Why: Verified both corrections already correctly present on the live site (body content, both instances). No mention of Piper/Gietzen in faq, excerpt, or meta_description. No further action needed.

    View the full record →

Contributors In This Page