Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification SEC·104

SEC · Security & Compliance Defined scope Fixed fee

Cloud IAM Permissions Audit

Every cloud identity checked against what it actually uses, with over-broad permissions tightened in safe batches to limit breach impact.

Fee · GST incl.
₹18,999
Duration
10 working days
Deliverables
7

01 Overview

Access in a cloud account tends to grow and rarely shrinks: the developer who needed production rights for one incident in 2023 still holds them, and a CI role became administrator because writing the exact policy was tedious. Using access analyser and CloudTrail records, we set each identity's granted permissions against what it has actually exercised over 90 days, then write least-privilege policies to replace the broad grants. Every change is proposed and reviewed with you before it is applied, and nothing goes live where it would break a working system.

02 Deliverables

7 items

What you receive at handover

  1. D01 Inventory of all users, roles, service accounts and access keys
  2. D02 Comparison of granted and used permissions over 90 days of activity
  3. D03 Least-privilege policies drafted and ready to apply
  4. D04 List of unused credentials and stale identities with a removal plan
  5. D05 Review of multi-factor authentication and root account configuration
  6. D06 Review of cross-account trust and external access
  7. D07 Documented quarterly access review process for your team

03 Outcomes

What should be true once it ships

  • A leaked or stolen key exposes far less than it would today
  • Access held by former staff and dormant credentials is found and removed
  • Your team gains a quarterly review it can repeat on its own

04 Process

How the 4 stages run

  1. Collect The identity inventory and activity logs are gathered and analysed
  2. Compare Each identity's granted permissions are measured against its real usage
  3. Propose Tighter policies are drafted and reviewed with the teams that own them
  4. Apply Changes are rolled out in agreed batches with rollback prepared

05 Fit & inputs

A good fit for

  • Cloud accounts where permissions have built up for years without review
  • Organisations where former staff may still hold valid access
  • Teams facing an audit that will ask for evidence of least privilege

What we need from you

  • Read-only security audit access to each cloud account in scope
  • Confirmation of the current owner of each service account
  • An agreed change window for applying the policy updates

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

That risk is why we rely on 90 days of real usage data and roll out in batches. Anything unclear is flagged, not guessed at.

Yes, using their equivalent identity services. Note your provider in the brief when you order.

Only with your written approval, one batch at a time. Nothing is removed unilaterally.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Security & Compliance

Web Application VAPT

Manual penetration testing of your web application with evidence for each finding and a retest, so real risks are fixed and proven fixed.

Manual penetration test of authentication, authorisation and business logic

Fixed fee · GST incl.

₹29,999

Duration

12 working days

SOC 2 Evidence Groundwork

Technical controls and automated evidence collection for a SOC 2 Type II audit, operating before your observation window opens.

Control gap assessment against the Trust Services Criteria in scope

Fixed fee · GST incl.

₹44,999

Duration

30 working days

DPDP Act Readiness Review

A gap assessment against the DPDP Act, 2023 covering consent, retention, notices and breach handling, with a prioritised remediation plan.

Inventory of personal data held across your systems, vendors and storage locations

Fixed fee · GST incl.

₹22,999

Duration

15 working days

GST included

₹18,999

Next step

Have a system that needs building, fixing or securing?