Scope and boundary
We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.
A point-in-time assessment of how your cloud accounts, administrative identities, network exposure, logging, and guardrails actually stand against the control outcomes your board, customers, and insurers ask about. We work from the evidence you can produce, rate the gaps by business impact, and hand you a sequenced plan a named owner can execute. Vendor-neutral by design.
For leaders who own cloud risk. Advisory and readiness work. Not a penetration test, not an audit, not a certification.
The Cloud Security Configuration Review Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. The lane-specific layer is a cloud control map covering account and tenancy structure, identity and privilege, network and exposure, logging and detection readiness, data protection, and backup and recovery posture.
We agree the systems, environments, data types, review period, and exclusions in writing before any evidence is collected, with a stated reason for each exclusion.
A defined request for client-provided exports, screenshots, screen shares, and documents. We do not request administrator credentials and we do not run automated scans.
Short, targeted conversations with the people who own the controls, to test how the design actually operates rather than how a diagram says it should.
We rate each observed gap by likelihood and business impact, and record evidence strength alongside it. Severity is a business-context rating, not a vulnerability score, and the method is explained in the report.
Each finding states what we observed, why it matters, the supporting evidence, the recommended action, and a named accountable owner.
Immediate actions and a sequenced roadmap that balances risk reduction, dependencies, effort, and cost, with named owners and an executive readout for leadership.
Typical timebox: 3 to 5 weeks after kickoff and timely evidence access. Larger, multi-environment, or high-complexity engagements are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins.
We assess client-provided configuration exports, architecture diagrams, identity and access exports, network and firewall rule exports, logging and retention settings, and policy documents, supplemented by screen shares where a live view is faster than an export. We reconcile what the documents claim against what the exports show.
We do not request administrator credentials, we do not connect tooling to your environment, and we do not run automated scans. The review is manual and evidence-based, so it stays inside a boundary you can see and revoke.
Your accounts, environments, and administrative boundaries mapped against the control outcomes in scope, with the evidence produced for each.
Every observed gap with the evidence, a business-context severity, an accountable owner, and a target date. The working document the engagement is built around.
Administrative access, standing privilege, and break-glass paths reviewed against least-privilege intent, with the exposures that matter flagged for tightening.
Internet-facing exposure, network segmentation, and logging and detection readiness described in business terms, not raw tool output.
A vendor-neutral description of the target-state design and its trade-offs, so a build decision is grounded in evidence rather than a marketing diagram.
Immediate actions and a sequenced plan balancing risk reduction, dependencies, effort, and cost, with an executive readout.
Synthetic sample — not client data. It contains no client information and is not a finding about any organization.
The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.
| Control area | Observed evidence | Severity | Recommended move |
|---|---|---|---|
| Administrative identity | Privileged roles exist without a documented break-glass path or periodic access review. | High | Define break-glass, enforce review cadence, assign an identity owner. |
| Network exposure | Two management ports are reachable from the public internet outside the documented allow list. | High | Restrict to known sources, confirm the allow list, record the exception owner. |
| Logging readiness | Control-plane logging is enabled but retention is shorter than the stated evidence requirement. | Moderate | Extend retention to the requirement, confirm a named reviewer of the log evidence. |
Final ratings depend on the environment, the evidence, and the agreed method. We do not convert findings into a purported certification score.
We organize findings using NIST CSF 2.0 as the structure and reference CISA's Cross-Sector Cybersecurity Performance Goals as a supporting baseline. These frameworks shape how we describe outcomes; they do not make this a NIST or CISA audit, and we name no cloud provider as a capability claim.
DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.
Accountable owner: DSE delivery leadership.
This is a point-in-time assessment of the cloud accounts, identities, configuration evidence, and documentation in the agreed scope. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance or any enforcement or examination outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), does not run penetration tests, and does not resell licenses. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.