Establish the landing-zone baseline
Define approved regions, identity federation, logging destinations, network patterns, encryption requirements and break-glass access before application teams create exceptions.
Make ownership visible
Tag or otherwise map accounts, subscriptions, projects, data stores and public endpoints to accountable teams. Unowned cloud resources become persistent security and cost risk.
Protect the change path
Review infrastructure code, restrict deployment identities, scan dependencies and compare production configuration with the approved baseline. Manual console changes should be visible and exceptional.
Prepare for provider-scale evidence
Centralise audit, identity, network and workload telemetry. Test the process for isolating a workload, revoking a role and preserving logs across accounts.
