Cloud environments often start small and grow organically. A few servers become dozens of services, and nobody is quite sure what is running, who has access or what it costs. Use this checklist to review your setup.
Accounts and access
- Root/owner account secured with MFA and not used for daily work
- Individual user accounts with role-based permissions
- Access removed promptly when people leave
- Separate environments (or accounts) for production and non-production
Security
- Security groups and firewalls allow only required traffic
- Operating systems and services patched on a schedule
- Secrets stored in a secrets manager, not in code
- Encryption enabled for storage and databases where appropriate
Networking
- Clear network layout with private subnets for databases and internal services
- Public exposure limited to load balancers or gateways
- DNS and SSL certificates tracked with renewal alerts
Backups and recovery
- Automated backups for databases and critical storage
- Backups tested by actually restoring them
- Documented recovery steps and responsibilities
Monitoring and alerting
- Uptime, CPU, memory, disk and error-rate monitoring
- Alerts routed to people who can act on them
- Centralised logs retained for an agreed period
Deployments
- Infrastructure changes tracked (ideally as code)
- CI/CD pipelines instead of manual server changes
- Rollback plan for every release
Cost control
- Budgets and billing alerts configured
- Unused resources and old snapshots cleaned up
- Instance sizes reviewed against actual usage
Reviewing this list every quarter keeps your cloud environment secure, reliable and predictable as the business grows.