<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloud Security — Things Worth Sharing</title><description>Posts tagged Cloud Security.</description><link>https://cloudsecop.net/</link><item><title>AWS Security Maturity Model v2: 4 phases in practice</title><link>https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</guid><description>Practical walk-through of AWS Security Maturity Model v2: 74 controls across four phases (Quick Wins, Foundational, Efficient, Optimized), real ordering, traps, and Org mapping.</description><pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>AWS SMM Assessment Tool: scoring posture in an afternoon</title><link>https://cloudsecop.net/en/blog/aws-security-maturity-model-assessment-tool-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/aws-security-maturity-model-assessment-tool-en/</guid><description>Field notes from the AWS Security Maturity Model Assessment Tool across four phases (Quick Wins, Foundational, Efficient, Optimized): architecture, workflow, JSON/Excel export.</description><pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Assessment</category><category>Governance</category><author>KhaVan</author></item><item><title>AWS KMS Key Policies: get this right or lose your data</title><link>https://cloudsecop.net/en/blog/kms-key-policies-deep-dive-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/kms-key-policies-deep-dive-en/</guid><description>How KMS key-policy evaluation works: cross-account access, condition keys, grants, key rotation, production patterns. With JSON policy examples and a production checklist.</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>KMS</category><category>Encryption</category><category>IAM</category><author>KhaVan</author></item><item><title>GuardDuty auto-remediation: isolate EC2 and revoke IAM</title><link>https://cloudsecop.net/en/blog/guardduty-auto-remediation-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/guardduty-auto-remediation-en/</guid><description>An auto-remediation pipeline for GuardDuty using EventBridge and Lambda: isolate instances, snapshot for forensics, revoke credentials, and scale it across an Organization.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Automation</category><category>EventBridge</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS to GCP: keyless auth</title><link>https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</guid><description>Workload Identity Federation deep dive: why Service Account Keys are anti-pattern, AWS STS → Google STS exchange, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Running CSPM across a dozen AWS Landing Zones</title><link>https://cloudsecop.net/en/blog/cspm-multiple-aws-landing-zones/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cspm-multiple-aws-landing-zones/</guid><description>How I built an in-house CSPM engine scanning many AWS Landing Zones in parallel with Prowler, storing findings in D1 and artifacts in R2, into one Security Operations dashboard.</description><pubDate>Tue, 24 Dec 2024 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>CSPM</category><category>Prowler</category><category>Cloudflare</category><author>KhaVan</author></item></channel></rss>