ChatGPT SearchSep 22, 2026
If you mean M&A / investment diligence on a company’s cloud environment, the highest-value check is:
Run a cloud-control review against CSA CCM/CAIQ, then verify it with evidence
The Cloud Security Alliance Cloud Controls Matrix (CCM) is specifically designed for cloud security assessment and covers IAM, encryption/key management, data security, logging, vulnerability management, incident response, resilience, supply chain, and shared responsibility. The current CCM/CAIQ v4.1 has 207 controls across 17 domains.
For diligence, I'd focus on these 10 checks:
- IAM: MFA, privileged accounts, dormant users, service accounts, least privilege, SSO.
- Public exposure: internet-facing storage, databases, admin interfaces, security groups/firewalls.
- Secrets & keys: where credentials live, rotation, KMS/HSM usage, who can access keys.
- Data: what sensitive data is in cloud, encryption at rest/in transit, backups, retention and deletion.
- Logging: centralized audit logs, retention, tamper resistance, alerting, and whether critical accounts/actions are monitored.