SysTools
Audit & Assessment Service

Cloud Security Assessment

A configuration and compliance audit of your AWS, Azure or GCP environment — we review how every service in scope is actually set up, check identity and access policies for gaps, examine how tenants and environments are kept apart, and measure it all against the audit frameworks you need to meet. This is a read-only review: nothing is exploited and nothing is changed. Please answer what you can; anything you are unsure of can be settled on the scoping call.

Progress 0% 0 of 0 answered 0 mandatory pending

Before you start

  • This is a configuration and compliance audit, not a penetration test. We review how your cloud is set up and compare it against the standards you need to meet. We do not attempt to break into anything, and we change nothing.
  • Please do not type real passwords, access keys or secrets into this form. Those are shared separately through a secure channel.
  • Fields marked * are needed before we can begin. Anything you are unsure of can be settled on the scoping call — pick "Not sure" and move on.

1 Assessment Details

Mandatory

Someone who can explain why a setting is the way it is. Without that, every difference from the standard gets written up as a gap.

Please note: the estimate in section 7 covers one round of assessment. How often it repeats is agreed when the scope is finalised.

2 Your Cloud Environment

Decides the timeline

This section decides the estimate. Rough numbers are fine.

Accounts

Cloud accounts / subscriptions
Regions in use

Servers

Servers or instancesEC2, Virtual Machines
Cloud users

Sharing and services

Separate customers or business units sharing this setup
Different cloud services in usesee the guide below

If this environment serves only your own organisation, put 1 for customers or business units.

How many cloud services? Each service has its own list of settings to check, so this moves the estimate most. If you do not know, use this guide: a simple setup using little more than servers, storage and logins is around 5; a typical business setup that also uses databases, backups, monitoring and keys is around 10; a large estate using containers, serverless and data pipelines as well is 20 or more.

A rough list is enough, and it does not have to be complete. If you would rather go through it on the call, leave this blank — the number above is what drives the estimate.

We only review the accounts listed here. Account IDs and login details are shared separately, not in this form.

3 Separation and Data

Mandatory

If they are only kept apart by the software, one coding mistake can expose one party's data to another, with nothing else standing in the way. Worth knowing before we start.

This decides how serious a finding is, so an approximate answer is fine. Anything unusual can go in the notes below.

4 Standards to Assess Against

Affects the timeline

One standard is included; each extra one adds time, because every finding has to be written up against it separately. If you are unsure, CIS Benchmarks is the usual choice — it is specific to your cloud provider and lines up with most other standards afterwards.

Full checklist gives a pass or fail against every control — longer, and what an auditor asks for. Problems only is shorter and focuses on what needs fixing.

5 How We Review

Nothing here needs an answer — it is what you are buying.

How the assessment runs

We turn the standards you chose into a checklist tailored to the services you actually run, then work through your settings against it. Nothing is changed at any point — this is a read-only review. Every gap is recorded against the check it fails and rated for how much it matters in your situation, and where you asked for a full checklist, every check that passes is recorded too. You get the report and a walkthrough with the people who did the work.

What we look for

Who can do what, and whether anyone has more access than they need. What is exposed to the internet that should not be. Whether storage and databases are readable by people who should not see them. Whether data is encrypted and who holds the keys. Whether activity logging is switched on everywhere and whether anyone would notice an alert. Whether backups exist and have ever been restored. And how customers, business units and live/test environments are kept apart.

What we will not do

This is an audit, not a penetration test. We do not attempt to exploit anything, run attack traffic, or change a single setting. If you need weaknesses actively exploited to prove impact, that is a penetration-testing engagement and is scoped separately.

6 How We Rate Findings

Every finding carries two things: a risk rating, and — where a per-control status is requested — a compliance status against each selected framework.

Risk ratingWhat it means
CriticalA control gap that leaves the environment exposed right now — unrestricted administrative access, publicly readable sensitive data, or no audit trail at all. Fix immediately.
HighA significant gap against the framework that materially weakens the environment, such as missing MFA on privileged accounts or unencrypted sensitive data.
MediumA gap that matters but is limited in reach, or is partly mitigated by another control that is working.
LowA minor deviation from the benchmark with limited practical impact. Worth closing to reach a clean baseline.
ObservationGood-practice or hardening advice beyond what the framework requires. Not a compliance gap.
Compliance statusWhat it means
CompliantThe control is implemented and evidence confirms it. Recorded as a pass, not omitted.
Partially CompliantThe control is implemented in some accounts, regions or services but not consistently across the scope.
Non-CompliantThe control is not implemented, or is implemented in a way that does not meet the framework requirement.
Not ApplicableThe control does not apply — typically because the service it governs is not in use. The reason is recorded.
Not VerifiedEvidence could not be obtained within the agreed access or window. Recorded honestly rather than assumed compliant.

Risk rating considers how exposed the resource is, what privileges the gap grants, how sensitive the data is, how many accounts or tenants are affected, and which compensating controls are genuinely working. After a re-audit each finding is marked Closed, Open, Partially Fixed, Compensating Control Implemented, Risk Accepted or Not Retested.

7 Timeline Estimate

These fill in automatically from your answers in sections 3 and 7. You can change them here if you need to.

Timeline inputs

Cloud accounts in scope
Services to reviewcounted from section 3
Servers or instances
Customers or business units sharing it
Standards to check againstcounted from section 7
People working on it at once
Re-audit roundsoptional, not included by default

Each service has its own list of settings to check, which is why the service count moves the estimate most. One standard is included; each extra one adds time, because every finding has to be written up against it separately.

Estimated duration 0 working days
Configuration review0
Reporting0
Re-audit0

Subject to final scope review, evidence availability and resource confirmation. The final timeline is confirmed after the complete scope has been reviewed and understood.

Save and Export Response

Your answers stay in this browser until you export or clear them.