← Security Hub guides

CLOUD SECURITY / THE TOP 10 SERIES

Top 10 CSPM issues to check in your cloud

A practical cloud security posture checklist covering identity, exposure, data protection, visibility, and recovery.

Truva Solutions · Guide · 19 Sep 2026

Read the practical guide ↓
10 CSPM issues. A numbered overview; every issue and action is explained in the article below.
Truva Solutions · Security Hub© 2026 TRUVA SOLUTIONSDownload infographic ↓

Before you start

CSPM means cloud security posture management. This is Truva’s practical checklist, not a vendor ranking or a universal severity order. The examples use AWS controls; equivalent checks and service behavior vary across Azure and Google Cloud.

A long findings list is not a remediation plan. Start with assets that are exposed, hold sensitive data, or can grant access to other systems. Confirm business context before changing a production control.

01

Public storage

Bucket policies and legacy access rules can expose information beyond its intended audience.

Restrict unintended public access.

Review both account-level protections and resource policies. Preserve intentionally public content only through an approved design.

Primary source ↗
02

Open management ports

Public administrative interfaces create avoidable paths into cloud workloads.

Close unnecessary internet access.

Review inbound rules for SSH, remote desktop, and management services. Prefer controlled private access paths.

Primary source ↗
03

Excessive permissions

Wildcard permissions can give a compromised identity control far beyond its task.

Replace broad grants with needed access.

Inspect effective permissions, including resource policies and role trusts, before narrowing access and testing the workflow.

Primary source ↗
04

Unprotected privileged accounts

Powerful accounts need stronger protection and limited routine use.

Protect privileged sign-in with MFA.

Review root or equivalent administrator protections, recovery procedures, and emergency access ownership.

Primary source ↗
05

Unused credentials

Credentials that outlive their purpose leave access available without a current business need.

Remove stale access safely.

Find inactive keys and accounts, confirm dependencies with owners, and remove or replace them through a controlled change.

Primary source ↗
06

Missing audit trails

Without a reliable activity record, investigations may not establish who changed what.

Record and protect cloud activity.

Verify trail coverage, delivery, retention, access restrictions, and integrity controls. Test that an event reaches your monitoring workflow.

Primary source ↗
07

Encryption gaps

Encryption depends on configuration and who can use the key, not just an enabled setting.

Review encryption and key access.

Check encryption for sensitive storage and databases; review key policies, rotation requirements, and recovery implications.

Primary source ↗
08

Public databases

A database should not be reachable from the internet simply because a default made it convenient.

Restrict database network exposure.

Inspect public-access settings, network routes, security rules, authentication, and the application’s intended connection path.

Primary source ↗
09

Unprotected recovery data

A configured backup job does not establish that recovery will work when needed.

Protect backups and test restores.

Check backup coverage and access controls, then test restoration against agreed recovery requirements.

Primary source ↗
10

Findings without owners

Posture improves when findings result in verified changes, rather than accumulating in a dashboard.

Assign, remediate, and verify.

Give each significant finding an owner and due date. Document justified exceptions and verify fixes on the next assessment.

Primary source ↗

Turn findings into verified fixes.

Start with your most exposed or sensitive workflow. Confirm the issue, assign an owner, make a controlled change, and keep evidence from the retest. These checks are a starting point, not proof of complete security or compliance.

Discuss a security assessment

Join the discussion

Page views

What are you seeing in your AI or cloud environment? Share a question or a practical lesson.

Comments are reviewed before publication. Your display name and comment will be public if approved. Please leave out confidential or personal information.

Enable JavaScript to read and submit comments.