In Cloud Auditing Best Practices, Michael Ratemo, Principal Consultant at Cyber Security Simplified, and cybersecurity executive Shinesa Cambric, provide a practical framework for assessing security, governance, risk, and controls across AWS, Microsoft Azure, and Google Cloud.
The book’s core theme: moving to the cloud does not mean transferring responsibility for security, governance, and control to the cloud provider.
Cloud environments introduce a different operating model, one built around shared responsibility, rapidly changing infrastructure, distributed identities, automation, and services that may span multiple cloud providers.
For The Reputiva Bookshelf – Week 1, we explore some of the lessons from the book that stood out to us and, more importantly, the questions organizations should be asking about their own cloud environments.
The question this book helps answer
As organizations increase their use of AWS, Microsoft Azure, Google Cloud and other cloud platforms, one question becomes increasingly important:
How do we know that the cloud environment is not only operational, but also secure, governed, auditable, and aligned with business risk?
One of the book’s recurring themes is the shared responsibility model. Moving workloads to a cloud provider does not transfer every security and control responsibility to that provider. Some controls remain the customer’s responsibility, while others require shared responsibility between the parties.
Shared responsibility simply means there are actions, tools, processes, capabilities, and controls that the CSP is responsible for and others that the cloud customer will be responsible for, and some that require joint responsibility for full control coverage.
IT Auditor Role
As an enterprise IT auditor, you will be responsible for reviewing and understanding the “qualified opinion” on the SOC report, as well as closely reviewing the scope of which trust principles have been covered and the time period of testing.
Practical Lessons from the Book
1. Start with the business purpose, not the technology.
An effective cloud audit begins by understanding why the environment exists, what business processes it supports, and which risks matter. That context determines the scope, applicable frameworks, and controls that should be assessed.
2. You cannot audit what you cannot see.
Cloud environments can contain virtual machines, networks, containers, serverless functions, applications, identities, and services spread across accounts, subscriptions, projects, and regions.
Asset inventory therefore becomes foundational. Auditors need to know what exists, who owns it, whether it is authorized, and whether shadow IT is present.
3. Identity remains one of the most critical control areas.
Across AWS, Azure, and GCP, cloud audits should examine privileged access, least privilege, MFA, role assignments, dormant accounts, and periodic access reviews.
The existence of IAM controls is not enough. The real question is whether access reflects actual business need.
4. Logging should never be assumed.
A cloud platform may provide extensive audit, activity, and sign-in logging capabilities, but organizations still need to verify that the right logs are enabled, retained, protected, and monitored.
Without reliable logging, it becomes much harder to demonstrate control effectiveness or reconstruct what happened during an incident.
5. Governance increasingly needs automation.
Landing zones, Infrastructure as Code, Policy as Code, tagging, configuration monitoring, and automated compliance checks can help organizations apply security and governance consistently at scale.
How would your environment answer these Questions?
If we were assessing a cloud environment, some of the first questions would be:
• Do we have an accurate inventory of our cloud assets?
• Who owns each account, subscription, project, and critical resource?
• Who currently has privileged access?
• Are security and audit logs enabled and retained appropriately?
• Can unauthorized configuration changes be detected?
• Are policies consistently enforced across environments?
• Are tagging and ownership standards being applied?
• Can cloud costs be traced back to accountable business owners?
• Could we produce evidence of our key controls if an auditor asked for it today?
Resources worth exploring
Landing Zones & Governance
- AWS Control Tower
- AWS Attribute-Based Access Control
- Azure Landing Zones
- Azure Tag Governance
- Google Cloud Blueprints
Policy, Configuration & Change Management
Cloud Security & Asset Visibility
Key takeaway
Cloud auditing is not simply checking whether controls exist.
It is determining whether those controls are appropriate for the organization’s risks, whether they are operating effectively, and whether sufficient evidence exists to demonstrate that effectiveness.
For Reputiva, this reinforces an important principle:
Cloud security, governance, architecture, cost management, and compliance should not be assessed in isolation. Together, they provide a clearer picture of whether an organization actually has control of its cloud environment.
The question for this week
If your organization had to demonstrate today that its cloud environment was secure, governed, and under control, how confident would you be in the evidence available?
What would be the first area you would audit: identity, configuration, networking, logging, data, or cost management?
Reputiva
Reputiva is a cloud, cybersecurity, and FinOps advisory firm helping SMEs reduce cyber risk, strengthen cloud environments, and manage technology costs with confidence. We publish practical insights on cloud security, identity, AI risk, compliance, and digital transformation.


