Reduce privilege paths
Identify users, roles, service identities, trust relationships and permissions that create unnecessary reach.
Damocles Cloud Security Review compares deployed cloud reality with the intended architecture and operating model, then prioritises the identity, exposure and resilience changes that reduce the greatest blast radius.
A service role with broad permissions, a public endpoint, a shared data store, weak administrative separation and missing audit logs can combine into an attack path that no single configuration check explains.
The review follows identity, network and data paths across the authorised cloud scope, compares them with the intended design and separates immediate risk reduction from structural improvements that require architecture or operating-model change.
Identify users, roles, service identities, trust relationships and permissions that create unnecessary reach.
Find public services, permissive network paths, shared data and management interfaces that are broader than intended.
Identify missing logs, alerting, backup, key-management and resilience controls needed to investigate and recover.
The scope can cover a landing zone, one workload, selected accounts or subscriptions, or a broader cloud operating model.
Users, groups, roles, service identities, federation, privileged access, cross-account trust and administrative separation.
Public services, private connectivity, security groups, routing, segmentation, management paths and service endpoints.
Public access, sharing, encryption, key use, retention, backups and sensitive-data handling.
Compute, containers, serverless functions, databases, queues, managed services and security-relevant defaults.
Audit logs, security events, retention, centralisation, alerting, source health and investigation readiness.
Backup, immutability, recovery paths, regional dependencies, administrative recovery and operational continuity.
Review cloud identities, configuration, networking, data services and operational controls to expose excessive access, unintended exposure and weak recovery or monitoring paths.
Roles, policies, federation and administrative access.
Public services, trust boundaries and private connectivity.
Storage access, encryption and sensitive-data exposure.
Compute, container and serverless configuration.
Credential storage, key lifecycle and service access.
Coverage, retention and visibility of material events.
Backups, recovery controls and critical dependencies.
Configuration baselines, exceptions and change controls.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles enumerates principals, roles, policies, trust relationships and privileged assignments and traces representative administrative paths.
Damocles identifies public endpoints, addresses and resource policies and corroborates approved exposure from an external position.
Damocles reviews virtual networks, security groups, network policy, routing and private-service boundaries against intended flows.
Damocles examines storage resource access, public settings, encryption, retention and representative identity permissions.
Damocles reviews key and secret stores, access policy, rotation metadata, workload retrieval paths and administrative custody.
Damocles reconciles required cloud log sources with enabled destinations, retention and representative event availability.
Showing 6 representative areas. The full governed matrix contains 14 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
The scoped technical behaviour relevant to cloud security review.
The scoped technical behaviour relevant to cloud security review.
A prioritised cloud review with configuration evidence, affected resources, remediation guidance and validation outcomes.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles uses a read-only cloud role and platform exports to trace identity, exposure, data and administrative paths, with bounded external checks where authorised. Configuration evidence is point-in-time and is not a complete cloud compliance assessment; write actions and resilience tests require separate approval.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Enumerates in-scope accounts, resources and policies through a read-only platform role and configuration exports.
Traces role assignments, policies, trust relationships and administrative paths to sensitive cloud resources.
Confirms approved public endpoints, storage exposure and network reachability from outside the cloud boundary.
Explains ownership, operational intent and remediation dependencies for sampled workloads and services.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Identity and privileged access | Damocles enumerates principals, roles, policies, trust relationships and privileged assignments and traces representative administrative paths. | Identity and privilege-path reviewer Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for identity and privileged access. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to identity and privileged access. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Identity and privileged access when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled identity and privileged access; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Public exposure | Damocles identifies public endpoints, addresses and resource policies and corroborates approved exposure from an external position. | Read-only cloud configuration reviewer Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for public exposure. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to public exposure. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Public exposure when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled public exposure; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Network controls | Damocles reviews virtual networks, security groups, network policy, routing and private-service boundaries against intended flows. | Read-only cloud configuration reviewer Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for network controls. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to network controls. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Network controls when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled network controls; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Storage configuration | Damocles examines storage resource access, public settings, encryption, retention and representative identity permissions. | Workload or service owner where evidence is required Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for storage configuration. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to storage configuration. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Storage configuration when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled storage configuration; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Key and secret management | Damocles reviews key and secret stores, access policy, rotation metadata, workload retrieval paths and administrative custody. | Workload or service owner where evidence is required Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for key and secret management. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to key and secret management. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Key and secret management when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled key and secret management; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Logging | Damocles reconciles required cloud log sources with enabled destinations, retention and representative event availability. | Workload or service owner where evidence is required Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| Monitoring and alerting | Damocles reviews alert rules, coverage, destinations and operational ownership for selected cloud security events. | Read-only cloud configuration reviewer Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| Workload configuration | Damocles examines representative workload identity, image or runtime settings, exposed interfaces, update controls and service configuration. | Workload or service owner where evidence is required Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested workload configuration object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Data protection | Damocles traces classified data through selected storage, processing, transfer and deletion controls using configuration and owner evidence. | Read-only cloud configuration reviewer Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for data protection. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to data protection. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Data protection when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled data protection; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Resilience and recovery | Damocles reviews backup, replication, recovery settings and documented exercises without claiming live recovery unless observed. | Read-only cloud configuration reviewer Architecture, dependency list, monitoring view, authorised failover window and rollback owner. | A timestamped failover observation showing state, convergence, service checks, monitoring and recovery or rollback. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed only when a customer-approved recovery or failover scenario, observer and rollback window are available. Limit: The result covers the exercised failure mode; activity stops at the rollback threshold and does not predict every compound failure. |
| Administrative paths | Damocles traces console, API, automation and emergency administrative paths to sensitive accounts and resources. | Read-only cloud configuration reviewer Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Ownership and operational responsibilities | Damocles maps sampled resources and controls to named service owners, platform responsibilities and remediation dependencies. | Workload or service owner where evidence is required Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for ownership and operational responsibilities. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to ownership and operational responsibilities. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Ownership and operational responsibilities when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled ownership and operational responsibilities; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Platform-specific applicability | Damocles records account, subscription or project, region, service and shared-responsibility constraints for every sampled conclusion. | Read-only cloud configuration reviewer Assessment requires read-only cloud access, account inventory, representative resources, owners and configuration exports, selected specifically for platform-specific applicability. | Evidence records the account, principal, policy, endpoint, network, storage, key, log or workload configuration evidence relevant to platform-specific applicability. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Platform-specific applicability when the platform resource and responsibility are included in the read-only review. Limit: The conclusion is limited to the sampled platform-specific applicability; findings are vendor-neutral and point-in-time; write actions, live resilience and complete compliance remain outside scope. |
| Configuration review versus cloud compliance | Damocles distinguishes point-in-time configuration findings from broader governance, operational effectiveness and cloud compliance. | Workload or service owner where evidence is required Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results; the record names the tested configuration review versus cloud compliance object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | The scoped technical behaviour relevant to cloud security review. | Scoped observations and coverage status that a qualified assessor may consider. | Applies: Only when the customer confirms that the framework and environment are applicable. Limit: Exact identifiers and licensed text are withheld; this is not certification or a complete framework assessment. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | The scoped technical behaviour relevant to cloud security review. | Scoped observations and coverage status that a qualified assessor may consider. | Applies: Only when the customer confirms that the framework and environment are applicable. Limit: Exact identifiers and licensed text are withheld; this is not certification or a complete framework assessment. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Cloud security review work.
Records coverage matrix produced from the authorised Cloud security review work.
Records retest and residual-risk record produced from the authorised Cloud security review work.
Records cloud identity and exposure map produced from the authorised Cloud security review work.
Records cloud configuration evidence produced from the authorised Cloud security review work.
Records ownership and remediation matrix produced from the authorised Cloud security review work.
A prioritised cloud review with configuration evidence, affected resources, remediation guidance and validation outcomes.
The statement of work defines providers, accounts, subscriptions, projects, regions, workloads, evidence methods and whether engineering support is included.
Assess identity, account structure, networking, logging, guardrails and administrative controls used by multiple workloads.
Assess one business service and its identities, data stores, network paths, secrets, logging and recovery dependencies.
Focus on federation, privileged roles, service identities, cross-account trust and permission paths.
Identify public services, management paths, storage, APIs and network controls exposed beyond the intended design.
Assess evidence availability, alerting, retention, backup separation, restoration and response readiness.
Review the target design before cutover or validate the deployed environment after major cloud change.
Read-only access, configuration exports, architecture evidence and customer interviews are selected according to the provider and authorised scope.
Confirm critical workloads, data sensitivity, identities, providers and the intended operating model.
Gather configuration, identity, network, logging, data and workload evidence using approved methods.
Follow identity, data and network paths that could expand attacker reach or operational impact.
Confirm material misconfiguration, design weakness and missing detection or recovery capability.
Separate immediate quick wins from structural identity, network and operating-model improvements.
Support architecture decisions and review changed configuration where included.
The review should make identity and exposure paths visible to technical teams while giving leaders a clear view of material risk and required investment.
Material cloud exposure, affected business services, likely impact and the decisions requiring attention.
Identity, network, data and administrative relationships that define blast radius.
Affected services, evidence, risk, conditions and specific remediation guidance.
High-value changes that can reduce exposure without major redesign.
Longer-term identity, landing-zone, logging, recovery and governance improvements.
A technical review with cloud, security and platform owners to agree the implementation path.
The customer provides the authorised account or subscription scope, read-only access or exports, architecture diagrams, workload owners, identity and federation context, critical data and service information, and any known incidents or audit concerns.
Where evidence is incomplete, Damocles records the limitation and avoids presenting an unsupported conclusion. Production changes are not made unless separately authorised as engineering work with change control and rollback.
The report or service record is the beginning of remediation, not the end of the engagement. These steps keep the outcome usable after formal delivery.
Damocles walks the customer through the findings, evidence, affected scope, dependencies and uncertainty so there is agreement on what requires action.
Each material recommendation is allocated to the team that can implement it, with a clear expected outcome and realistic dependency on other changes.
Quick risk reduction, structural change, compensating controls and longer-term engineering are separated so the customer can plan the work sensibly.
Configuration records, change references, screenshots, test results, source state or other agreed evidence are retained for later review.
Where included, Damocles reviews the changed state, performs a retest or reassessment, and records whether the original exposure is resolved, reduced or still present.
Issues that cannot be fully removed remain visible with the accepted limitation, compensating control, review date and decision owner.
The proposal identifies the authorised scope, delivery method, assumptions, customer inputs, working window, deliverables, briefing, remediation support and any included retest or follow-up. Fixed-scope engagements are priced against that agreed boundary; retainers and managed services use the recurring quantity and service model stated in the schedule.
When the environment, target count, repositories, locations, access, service coverage or required evidence changes materially, Damocles records the impact before continuing. The customer can approve a variation, reduce the scope, defer the additional work or create a separate engagement. Hidden scope expansion is avoided because it produces poor testing and unreliable delivery dates.
Third-party licences, specialist platforms, travel, after-hours work, emergency response, remediation engineering and work outside the agreed deliverables are included only when listed in the proposal. Existing customer technologies can be used where they are supported and suitable; Damocles does not require a particular vendor simply to deliver the service.
Guardian can retain each material finding, affected service, owner, due date, remediation plan, evidence and closure review alongside other customer risks and actions.
This allows cloud, security and leadership teams to distinguish immediate exposure from longer-term architecture work and report progress using the same operational record.
The final answer depends on the customer environment and scope, but these are the points that should be resolved before work begins.
Timing depends on scope, access, environment stability, customer availability and the review depth required. The proposal states the expected delivery window and the assumptions that can change it.
Yes, but the change is recorded. Damocles explains the coverage, timing and commercial impact before additional work is performed.
Yes. Internal teams, developers, cloud partners, infrastructure providers and MSPs can participate where responsibilities, access and communication paths are clear.
Priority considers practical exploitability or failure likelihood, exposure, affected business capability, data, privilege, dependency, available compensating controls and remediation effort.
Remediation guidance and handover are included as stated in the proposal. Implementation, managed change, emergency work and extensive engineering are separate unless expressly included.
Closure uses the method suitable for the issue: retesting, rescanning, code or configuration review, operational evidence, restored source health, tabletop follow-up or another agreed validation method.
Tell us the providers, account structure, critical workloads, data sensitivity and current concern. We will define the evidence, access and review depth required.