AUD / AUD-04
Cloud and collaboration security review
A review of a tenant’s security configuration and usage: identities, sharing, connected applications, logs and responsibilities.

WHEN IT HELPS
A focused response
to a defined need.
CIO or cloud owner; Microsoft 365, Google Workspace or public-cloud migration, or uncontrolled external sharing.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Review roles and policies
- data exposure
- third-party applications, retention and detection capability
Deliverables
- Gap inventory
- responsibility matrix
- recommendations by service and available licence
Acceptance evidence
Reviewed critical settings are documented with their observed state, target state and business impact of change.
DELIVERY
How the work is structured.
Approach
Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.
Prerequisites & responsibilities
Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.
Scope factors
Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.
Questions to clarify
Which services are actually used? Which licences are enabled? Where are data and logs located?
IMPORTANT BOUNDARIES
The review covers named services, not every provider product; paid options must be identified.
Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A charity shares donor documents through open links. Project: review the tenant and collaboration spaces. Target outcome: named owners and a link-restriction plan; closure is tested with affected partners.
Scenario 02
A services company assumes its cloud subscription is secure by default. Project: review access, storage and logging. Target outcome: explicit responsibilities and configuration fixes; provider security does not replace customer controls.
Technology and reference context
Microsoft 365, Google Workspace, AWS or Azure as scoped; applicable vendor documentation.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
