Cloud Infrastructure Posture Bundle
The AWS, Azure and Google Cloud Infrastructure Posture Kits together. Three clouds whose top misconfigurations barely overlap, assessed with the same five modules on one scoring scale, so a multi-cloud estate gets three directly comparable numbers. 20% off buying separately.
What this actually gives you
- Why the set: three clouds whose top misconfigurations barely overlap, one research base, one scoring scale — three directly comparable numbers rather than three reports written to different standards.
The 2026 data that shaped these kits shows near-zero overlap between each cloud's top misconfiguration categories — AWS leads on raw public exposure, Azure on misconfigured services and identity gaps, Google Cloud on identity hygiene despite the best network posture of the three. So each got its own kit, on one scoring scale, and this is all three.
AWS Cloud Infrastructure Posture Kit — 76% of scanned accounts publicly exposed; root and IAM hygiene, S3 exposure, CloudTrail, and the fourteen metric-filter and alarm pairs where the filter exists and the alarm has no subscriber. CIS AWS Foundations v3.0.0.
Azure Cloud Infrastructure Posture Kit — one identity to Key Vault, Storage and VMs in minutes; Key Vault and Storage weighted highest, both the CIS Azure and Microsoft Cloud Security Benchmarks, and no re-run of the Entra ID review the M365 kit already did.
Google Cloud Platform Posture Kit — 8% exposed, 87% with weak IAM; the default Compute Engine service account, JSON keys where federation should be, and the AI/ML workload surface the other two do not have. CIS GCP Foundation v4.0.0.
Why the set: the three kits share a research base and a scale, so the board sees one cloud's posture against the others rather than three reports written to different standards. The executive summary template in each is the same page.
What's in this bundle
AWS Cloud Infrastructure Posture Kit
Three in four scanned AWS accounts have something publicly exposed right now. What one exposed S3 bucket, one over-permissioned IAM role or one leaked access key can actually reach — scored against the CIS AWS Foundations Benchmark v3.0.0. First of a three-cloud trilogy on one scoring scale.
Azure Cloud Infrastructure Posture Kit
One compromised identity reached Key Vault, Storage and Virtual Machines in minutes, in a chain Microsoft's own security team documented in 2026. Azure's dominant risk is identity, not raw exposure, and this kit is shaped for it: Key Vault and Storage weighted highest, both the CIS Azure and Microsoft Cloud Security Benchmarks cited, and no re-run of the Entra ID review M365-01 already did. Second of the three-cloud trilogy on one scoring scale.
Google Cloud Platform Posture Kit
Google Cloud has the best network-exposure numbers of the three clouds by a wide margin, and almost exactly the same identity problem as the other two. This kit is about the gap between those facts: 8% exposed, 87% with weak IAM. Scored against CIS GCP Foundation Benchmark v4.0.0, with an AI/ML workload surface the other two cloud kits do not have. Third of the trilogy on one scoring scale.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee