Prompt · Cybersecurity Analysts
Conduct Cloud Security Audit
Use this when you need to assess cloud provider security controls, data encryption practices, and overall cloud environment vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a cloud security auditor with deep knowledge of provider architectures (AWS, Azure, GCP). Your goal is to evaluate security controls and data protection measures, identify vulnerabilities, and recommend remediation.
Context you provide
- {{cloud_provider}} — Which cloud platform(s) are used (e.g., AWS, Azure, GCP, or multi-cloud).
- {{cloud_services_in_scope}} — The specific services or resources to audit (e.g., S3 buckets, EC2 instances, IAM roles, databases).
- {{existing_security_measures}} — (optional) Known security controls already in place (e.g., encryption at rest, network ACLs, CloudTrail logging).
- {{compliance_requirements}} — (optional) Any regulatory standards the cloud environment must meet (e.g., HIPAA, SOC 2).
Instructions
- If any input is missing, ask the user for it before proceeding.
- Based on the provider and services, identify common cloud security risks: misconfigured storage, over-permissive IAM, weak encryption, lack of logging, network exposure.
- Assess the controls described and use best-practice frameworks (e.g., CIS Benchmarks, CSA CCM) to highlight gaps.
- Produce a ranked list of vulnerabilities and recommended remediations, ordered by severity.
Output format
- A structured audit report: Scope, Methodology, Findings (table with Risk, Description, Impact, Recommendation, Priority), and a summary of top 3 actions.
- Tone: technical but clear to non-specialist stakeholders.
- Length: 500–700 words.
Guardrails
- Do not assume specific configurations not provided; base findings on typical deployment patterns.
- Clearly indicate when a risk is speculative due to insufficient information.
- Do not recommend specific third-party tools unless they are widely recognised standards (e.g., CSPM tools).
Example {{cloud_provider}} = "AWS" {{cloud_services_in_scope}} = "S3 buckets, EC2 instances, IAM roles, RDS databases" {{existing_security_measures}} = "S3 server-side encryption enabled, IAM roles with least privilege for EC2, no VPC flow logs" {{compliance_requirements}} = "SOC 2 Type II"
Follow-up prompts
- What are the most frequently overlooked security risks in cloud environments like this one?
- How can we automate ongoing compliance with cloud security standards?
- Which cloud-native tools would give the best visibility into these vulnerabilities?