{"id":17928,"date":"2025-04-21T16:05:04","date_gmt":"2025-04-21T13:05:04","guid":{"rendered":"https:\/\/oberig-it.com\/uncategorized\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/"},"modified":"2025-05-02T16:06:13","modified_gmt":"2025-05-02T13:06:13","slug":"stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security","status":"publish","type":"post","link":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/","title":{"rendered":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security"},"content":{"rendered":"<p>Mismanaging configurations in your multi-cloud environment can put you at an elevated risk for cyber attacks. In the first installment of our \u201cStronger Cloud Security in Five\u201d blog series, we outline five best practices for boosting your cloud configuration management.<\/p>\n<p>A misconfigured web application firewall. A publicly accessible and unprotected cloud database. An overprivileged user identity. Lax access control to containers. Unchanged default credentials.<\/p>\n<p>Those are just some of the many configuration oversights and mistakes that attackers can leverage to breach your cloud environment, hijack user accounts, steal data and more. In addition, having misconfigured cloud resources puts your organization on the wrong side of regulatory compliance, and thus open to costly penalties, fines and litigation.<\/p>\n<p>In a vacuum, it would seem simple to button up most cloud misconfigurations. Surely, we can all agree that leaving an Amazon Web Services (AWS) Simple Storage Service (S3) storage bucket open to anyone on the internet is a no-no. Yet, the \u201c<a href=\"https:\/\/www.tenable.com\/cyber-exposure\/tenable-cloud-risk-report-2024\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Tenable Cloud Risk Report 2024<\/span><\/a>,\u201d based on an analysis of millions of cloud resources scanned through the Tenable Cloud Security platform, found that 74% of organizations have publicly exposed cloud storage.<\/p>\n<p>The reality is that cloud misconfigurations are prevalent. In fact, misconfigurations and inadequate change controls ranked first on the Cloud Security Alliance\u2019s \u201cTop Threats to Cloud Computing 2024&#8243; report. \u201cGiven a cloud\u2019s persistent network access and infinite capacity, misconfigurations can have wide-reaching impacts across an organization,\u201d the CSA tells us in that report.<\/p>\n<p>Why do even large multinationals \u2013 with massive resources and stellar IT, cybersecurity and compliance staff \u2013 routinely fail to properly configure their cloud environments?<\/p>\n<p>In a nutshell: With cloud environments having myriad moving parts and being so dynamic, managing configurations is complicated if you lack the proper processes and tools.<\/p>\n<p>Here are <a href=\"https:\/\/www.tenable.com\/lp\/cloud\/fiveminutes\/?_gl=1*cbt9qj*_gcl_au*MTgzODg5MDU0OS4xNzQ1ODUwNjUw*_ga*MTQzNDQ5MjI1NC4xNzM3OTYzMjMz*_ga_HSJ1XWV6ND*MTc0NjE4OTMyOC40Ny4xLjE3NDYxOTA3ODguNTQuMS40NTIzMjIzNA..\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">five best practices<\/span><\/a> you can apply immediately to harden your cloud configurations.<\/p>\n<h4>1 &#8211; Centralize and automate the configuration management of your multi-cloud environment<\/h4>\n<p>If your organization is like most others, it uses multiple cloud security providers (CSPs) \u2014 each with its own configuration settings and with its own shared responsibility model for divvying up security tasks with customers.<\/p>\n<p>That\u2019s why you need a vendor-agnostic, centralized cloud-native application protection platform (CNAPP) with a strong cloud security posture management (CSPM) component.<\/p>\n<p>With <a href=\"https:\/\/www.tenable.com\/source\/cloud-security-posture-management\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">CSPM tools<\/span><\/a>, you\u2019ll be able to centrally harden configurations across your multi-cloud environment by consistently and continuously adopting, monitoring and enforcing security policies in areas such as access control and data encryption.<\/p>\n<p>Without an automated, centralized system, you won\u2019t have holistic and comprehensive visibility of your configurations across all your clouds and your organization will be at heightened risk of cyber attacks.<\/p>\n<p>CSPM allows you to continuously scan all your cloud assets and resources and get an unobstructed view of all your detected misconfigurations. Then you can prioritize and document their remediation in compliance reports for your leaders, auditors and regulators.<\/p>\n<h4>2 &#8211; Implement least-privilege access across your multi-cloud environment<\/h4>\n<p>User and machine identities with excessive privileges pose a major risk in cloud environments because during a breach attackers can leverage those permissions to move deeper into your network. \u201cInitial malicious access attempts on cloud resources frequently target user credentials,\u201d the U.S. Cybersecurity and Infrastructure Security Agency (CISA) points out in its publication \u201cUse Secure Cloud Identity and Access Management Practices.\u201d<\/p>\n<p>Thus, your CNAPP should have a comprehensive cloud infrastructure entitlement management (CIEM) component with granular identity and access management (IAM) capabilities. That\u2019ll allow you to audit your multi-cloud identities and ensure they have the minimum access rights and capabilities they need. This is the concept of least privilege.<\/p>\n<p>At a high level, you need to continuously discover all of your cloud infrastructure\u2019s human and machine identities; understand their scope of cloud-resource access and permissions; assess identities\u2019 level of risk; and make necessary least-privilege adjustments.<\/p>\n<h4>3 &#8211; Automatically check configurations against compliance frameworks<\/h4>\n<p>Offering policy-as-code (PaC), your CNAPP should automate the process of codifying policies; regularly checking how compliant your multi-cloud environment is with industry, regulatory and internal compliance frameworks; and of generating in-depth audit reports. It should provide actionable findings and automate the process of fixing insecure and faulty configurations.<\/p>\n<p>This will yield multiple benefits for your organization, including:<\/p>\n<ul>\n<li>Quieting alert noise<\/li>\n<li>Proactively managing compliance<\/li>\n<li>Prioritizing remediation based on risk<\/li>\n<li>Boosting security operations<\/li>\n<\/ul>\n<h4>4 &#8211; Secure your Kubernetes clusters<\/h4>\n<p>Trying to manually assess the security of your Kubernetes clusters and fix configuration issues is a losing proposition, especially because many Kubernetes resources are ephemeral and come with default configurations. As Tenable Senior Principal Product Marketing Manager Lior Zatlavi explains in a blog: &#8220;The complexity of Kubernetes, combined with its dynamic and distributed nature, makes it a daunting task to ensure that clusters are secure from threats.\u201d<\/p>\n<p>That\u2019s why your CNAPP should have a <a href=\"https:\/\/www.tenable.com\/cloud-security\/solutions\/kspm\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Kubernetes security posture management (KSPM)<\/span><\/a> tool that gives you:<\/p>\n<ul>\n<li>Complete, deep and contextual visibility into your Kubernetes resources, including nodes, namespaces, deployments, servers and service accounts<\/li>\n<li>An admission controller that facilitates deployment and management by enforcing policy-as-code<\/li>\n<li>Detection of misconfigurations by scanning Helm charts<\/li>\n<li>UI-driven container workload protection<\/li>\n<\/ul>\n<h4>5 &#8211; Ingest and enrich log data from your CSPs<\/h4>\n<p>Organizations often overlook the importance of monitoring and analyzing the event and activity logs from their cloud environments that their CSPs collect. In fact, logs are critical for configuration management.<\/p>\n<p>To gain granular insights into the causes and impacts of cloud misconfigurations and to respond appropriately, you need a CNAPP that enriches the logging data from your CSPs with security data and continuously analyzes risk.<\/p>\n<p>This enriched log data will give you context and actionable information to maintain consistent and secure configurations that reduce your risk and keep you compliant.<\/p>\n<p>Source: <a href=\"https:\/\/www.tenable.com\/blog\/cloud-configuration-security-best-practices-cnapp-ciem-cspm\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #0000ff;\">Stronger Cloud Security in Five: The Importance of Cloud Configuration Security<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mismanaging configurations in your multi-cloud environment can put you at an elevated risk for cyber attacks. In the first installment of our \u201cStronger Cloud Security in Five\u201d blog series, we outline five best practices for boosting your cloud configuration management. A misconfigured web application firewall. A publicly accessible and unprotected cloud database. An overprivileged user [&hellip;]<\/p>\n","protected":false},"author":850,"featured_media":17686,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[142],"tags":[],"class_list":["post-17928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u261d Oberig IT blog<\/title>\n<meta name=\"description\" content=\"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u261d Oberig IT blog\" \/>\n<meta property=\"og:description\" content=\"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u26a1 Oberig IT blog for integrator partners, vendors and end customers\" \/>\n<meta property=\"og:url\" content=\"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Oberig IT\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Oberig.disti\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-21T13:05:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-02T13:06:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1875\" \/>\n\t<meta property=\"og:image:height\" content=\"625\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Albekova Paula\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Albekova Paula\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u261d Oberig IT blog","description":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u26a1 Oberig IT blog for integrator partners, vendors and end customers","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/","og_locale":"en_US","og_type":"article","og_title":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u261d Oberig IT blog","og_description":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u26a1 Oberig IT blog for integrator partners, vendors and end customers","og_url":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/","og_site_name":"Oberig IT","article_publisher":"https:\/\/www.facebook.com\/Oberig.disti","article_published_time":"2025-04-21T13:05:04+00:00","article_modified_time":"2025-05-02T13:06:13+00:00","og_image":[{"width":1875,"height":625,"url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg","type":"image\/jpeg"}],"author":"Albekova Paula","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Albekova Paula","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#article","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/"},"author":{"name":"Albekova Paula","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d"},"headline":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security","datePublished":"2025-04-21T13:05:04+00:00","dateModified":"2025-05-02T13:06:13+00:00","mainEntityOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/"},"wordCount":959,"commentCount":0,"publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg","articleSection":["Articles"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/","url":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/","name":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u261d Oberig IT blog","isPartOf":{"@id":"https:\/\/oberig-it.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#primaryimage"},"image":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#primaryimage"},"thumbnailUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg","datePublished":"2025-04-21T13:05:04+00:00","dateModified":"2025-05-02T13:06:13+00:00","description":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security \u26a1 Oberig IT blog for integrator partners, vendors and end customers","breadcrumb":{"@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#primaryimage","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2025\/04\/8.jpg","width":1875,"height":625},{"@type":"BreadcrumbList","@id":"https:\/\/oberig-it.com\/en\/articles\/stronger-cloud-security-in-five-the-importance-of-cloud-configuration-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/oberig-it.com\/en\/"},{"@type":"ListItem","position":2,"name":"Stronger Cloud Security in Five: The Importance of Cloud Configuration Security"}]},{"@type":"WebSite","@id":"https:\/\/oberig-it.com\/en\/#website","url":"https:\/\/oberig-it.com\/en\/","name":"Oberig IT","description":"Distribution of complex IT and information security solutions","publisher":{"@id":"https:\/\/oberig-it.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/oberig-it.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/oberig-it.com\/en\/#organization","name":"Oberig IT","url":"https:\/\/oberig-it.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","contentUrl":"https:\/\/oberig-it.com\/wp-content\/uploads\/2023\/06\/logo-new.svg","caption":"Oberig IT"},"image":{"@id":"https:\/\/oberig-it.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Oberig.disti"]},{"@type":"Person","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/9d804f9c469169d256ca04bc0446793d","name":"Albekova Paula","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberig-it.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/267b2447d88f2254471421efc84e51964ec66e50c0a67b40f9346d135523b971?s=96&d=mm&r=g","caption":"Albekova Paula"},"sameAs":["https:\/\/oberig-it.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/17928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/users\/850"}],"replies":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/comments?post=17928"}],"version-history":[{"count":2,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/17928\/revisions"}],"predecessor-version":[{"id":17930,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/posts\/17928\/revisions\/17930"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media\/17686"}],"wp:attachment":[{"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/media?parent=17928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/categories?post=17928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oberig-it.com\/en\/wp-json\/wp\/v2\/tags?post=17928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}