# Cloud Security Assessment

> From $12K · Offensive Security · https://cisomarketplace.services/services/cloud-security-assessment

Security evaluation of cloud infrastructure and configurations

## In scope

- Cloud Infrastructure Review
- Container Security Assessment
- IAM Configuration Analysis
- Network Security Groups Evaluation
- Data Storage Security Review

## Deliverables

- Cloud Security Report
- Configuration Assessment Document
- Security Best Practices Guide
- Risk Mitigation Plan
- Architecture Recommendations

## Tiers

### Basic Cloud Assessment: $12K

Configuration review of 1 cloud provider, up to 3 accounts/subscriptions: IAM, network security groups, storage exposure and logging. Read-only access, tool-assisted plus manual validation.

Limits: cloud accounts 3

Includes:
- 1 cloud provider, up to 3 accounts/subscriptions
- IAM, network security group and storage configuration review
- Read-only, non-intrusive review
- Findings report with risk mitigation plan

Excludes:
- Container and Kubernetes review
- Benchmark mapping against a named framework
- Active exploitation of cloud attack paths
- Second cloud provider

### Advanced Cloud Assessment: $20K

Configuration review of 1 cloud provider, up to 10 accounts/subscriptions, adding container workload review, architecture recommendations and a control-by-control check against 1 named framework.

Limits: cloud accounts 10, frameworks 1

Includes:
- 1 cloud provider, up to 10 accounts/subscriptions
- Container and registry configuration review
- Check against 1 named benchmark/framework
- Architecture recommendations
- Configuration assessment document per account

Excludes:
- Second or third cloud provider
- Active exploitation / cloud penetration testing
- Remediation work in your accounts

### Enterprise Cloud Assessment: $35K

Multi-cloud assessment: up to 3 cloud providers and up to 25 accounts/subscriptions, with active testing of privilege-escalation and cross-account attack paths, container review and checks against up to 2 frameworks.

Limits: cloud accounts 25, frameworks 2

Includes:
- Up to 3 cloud providers, up to 25 accounts/subscriptions
- Active testing of IAM privilege-escalation and cross-account paths
- Container and orchestration review
- Checks against up to 2 frameworks
- Cross-cloud architecture recommendations

Excludes:
- Continuous monitoring after the engagement (see Cloud Security Monitoring)
- Application-layer penetration testing of hosted apps
- Remediation implementation

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=cloud-security-assessment
