Establish the landing-zone baseline

Define approved regions, identity federation, logging destinations, network patterns, encryption requirements and break-glass access before application teams create exceptions.

Make ownership visible

Tag or otherwise map accounts, subscriptions, projects, data stores and public endpoints to accountable teams. Unowned cloud resources become persistent security and cost risk.

Protect the change path

Review infrastructure code, restrict deployment identities, scan dependencies and compare production configuration with the approved baseline. Manual console changes should be visible and exceptional.

Prepare for provider-scale evidence

Centralise audit, identity, network and workload telemetry. Test the process for isolating a workload, revoking a role and preserving logs across accounts.

Start with identityMost cloud control failures become more serious when an identity is over-privileged, long-lived or poorly monitored.