
Fundamentals of Cloud Security Practices
Cloud security involves shared responsibilities to protect data and applications in cloud environments.
Page Summary
An introduction to cloud security fundamentals, opening with the 2019 Capital One breach caused by a misconfiguration rather than an AWS flaw. Built around the shared-responsibility model, it covers identity and access management as the highest-leverage control, network security architecture (VPCs, public/private subnets, security groups, secure administrative access), encryption at rest and in transit with key management, storage and database protection, secrets management, logging and threat detection, common vulnerabilities, compliance frameworks, and security-as-code automation.
Contributions
Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.
-
2 corrections applied: The Rhino Security Labs '21 ways to escalate privileges in AWS IAM' research was authored by Spencer Gietzen, not Scott Piper | Same attribution fix: the Rhino Security Labs IAM privilege-escalation research was by Spencer Gietzen, not Scott Piper
BeforeScott Piper's "AWS IAM Privilege Escalation" research; Piper's research, conducted at Rhino Security Labs
AfterSpencer Gietzen's "AWS IAM Privilege Escalation" research; Gietzen's research, conducted at Rhino Security Labs
Why: Verified both corrections already correctly present on the live site (body content, both instances). No mention of Piper/Gietzen in faq, excerpt, or meta_description. No further action needed.
View the full record →