Identity and Access Management (IAM)
Who can do what to which resource: members, roles, policy inheritance, service accounts and least privilege.
Security
25 topics explaining what each cloud service does, why it exists, and which certification tests it. Written in our own words — we explain concepts rather than paraphrasing documentation.
Identity, encryption, and detecting what goes wrong.
Who can do what to which resource: members, roles, policy inheritance, service accounts and least privilege.
Default encryption, customer-managed keys, rotation and secret handling — and the operational consequences of each choice.
Finding misconfigurations, detecting threats, understanding audit logs and running a detection and response capability.