CLD / CLD-02
Cloud security posture management — CSPM
Detect exposed cloud configurations or deviations from selected policies and organise remediation. CSPM tracks technical posture; it does not replace full event monitoring or application assessment.

WHEN IT HELPS
A focused response
to a defined need.
Rapidly created resources, accidentally public storage, excessive cloud permissions or difficulty tracking gaps across accounts and regions.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Least-privilege connection
- inventory
- tailored policies
- prioritisation
- ownership
- ticketing integration
- exceptions
- controlled remediation
- drift tracking
Deliverables
- Connected scope
- active policies
- gap dashboard
- workflows
- remediation procedures
- exception register
- coverage and handling-time metrics
Acceptance evidence
Intended accounts are covered; a test deviation is detected and assigned; remediation is verified; exceptions can expire; uncovered resources are explicitly listed.
DELIVERY
How the work is structured.
Approach
Inventory accounts and use; clarify responsibilities; design policies; pilot; test and deploy; organise drift, exceptions and operations.
Prerequisites & responsibilities
Customer: tenant/account access, billing, data owners, administrators and residency constraints. Provider: architecture and configuration under shared responsibility.
Scope factors
Clouds, accounts, regions, resources, tenants, clusters, connectors and automation maturity. Consumption, transfers, storage and licenses are separate from the service.
Questions to clarify
Which accounts are inventoried? Who fixes a resource created by a project team? Can some deployments be blocked without affecting production?
IMPORTANT BOUNDARIES
Connectors and permissions determine coverage. Automated remediation can break a service; begin with observation and approval before automating risky actions.
Capabilities vary by edition, region and availability status. A posture score is neither certification nor a guarantee of complete detection.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A SaaS company discovers publicly accessible storage. Project: review permissions and establish drift controls. Target outcome: corrected exposure and detection of similar future changes without concluding that no prior access occurred.
Scenario 02
A mid-sized company uses multiple cloud accounts. Project: consolidate gaps and assign each resource to an owner. Target outcome: manageable remediation; ownerless accounts remain priority governance gaps.
Technology and reference context
Examples: native provider posture capabilities or a dedicated CSPM platform, according to actual clouds and licensing.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
