Cloud Security Risk Assessment Request Form
Submit details about your cloud environment, current controls, and assessment priorities so the security team can evaluate risk and plan follow-up.
Requestor and Organization Details
Requestor full name
*
First Name
Middle Name
Last Name
Job title / role
*
Work email
*
example@example.com
Company / organization name
*
Department or team
Primary contact method
*
Email
Phone
Other
Cloud Environment Scope
Cloud provider(s) in scope
*
AWS
Microsoft Azure
Google Cloud Platform
Oracle Cloud
Alibaba Cloud
Other
Environment type(s) in scope
*
Production
Staging
Development
Test
Hybrid
Multi-cloud
Other
Number of cloud accounts / subscriptions / projects
*
Regions or geographies in scope
*
Brief description of cloud workloads/services to be assessed
*
Architecture summary or documentation link/reference
Assets and Data Classification
Asset / Service Categories In Scope
*
Data Types Stored, Processed, or Transmitted
*
Public
Internal
Confidential
Sensitive Business Data
Customer Data
Regulated Data
Other
Highest Data Sensitivity Level in Scope
*
Please Select
Public
Internal
Confidential
Sensitive
Highly Sensitive
Regulated
Estimated Number of Assets in Scope
*
Any Internet-Facing Systems Included?
*
Yes
No
Current Security Controls
Is multi-factor authentication (MFA) enabled for cloud access?
*
Yes
No
Partially
Not sure
Are access permissions aligned with least-privilege principles?
*
Yes
No
Partially
Not sure
Is data encrypted at rest in the cloud environment?
*
Yes
No
Partially
Not sure
Is data encrypted in transit in the cloud environment?
*
Yes
No
Partially
Not sure
Which statement best describes your key management approach?
*
Please Select
Provider-managed keys
Customer-managed keys
Customer-held keys
Mixed approach
Not sure
Other
Are network segmentation or security groups in place?
*
Yes
No
Partially
Not sure
Does your current cloud security program feel mature?
*
1 - Very immature
2 - Early stage
3 - Developing
4 - Well established
5 - Highly mature
Describe any notable control gaps or concerns.
Identity, Access, and Logging
Is centralized identity federation or single sign-on used?
*
Yes
No
Partial
Not sure
Is privileged access limited to authorized personnel?
*
Yes
No
Partial
Not sure
How are service accounts or API keys managed?
*
Stored in a secrets manager
Rotated regularly
Restricted to limited personnel
Monitored for misuse
Not formally managed
Other
Are access reviews performed on a regular basis?
*
Yes
No
Planned
Not sure
Are cloud audit logs enabled?
*
Yes
No
Partial
Not sure
Is centralized log retention in place?
*
Yes
No
Partial
Not sure
What monitoring and review practices are in use?
Alerting tool in use
Security events reviewed regularly
Centralized dashboard
Escalation process defined
Not in place
Other
Describe any known access anomalies or audit findings.
Assessment Priority and Follow-up
Reason for Assessment Request
*
Please Select
New cloud initiative
Scheduled review
Significant environment change
Incident response follow-up
Audit or compliance need
Executive request
Other
Business Impact if Risks Are Found
*
Desired Assessment Depth
*
Please Select
High-level review
Moderate assessment
Detailed assessment
Comprehensive assessment
Urgency / Priority
*
Low
Normal
High
Critical
Preferred Timeline / Target Date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Follow-up Requirements
Kickoff call requested
Stakeholder meeting requested
Provide assessment summary report
Review findings workshop
No follow-up needed
Other
Primary Goals of the Assessment
*
Attachments / Supporting Documents
Upload a File
Drag and drop files here
Choose a file
Cancel
of
Additional Notes or Special Instructions
Submit Request
Should be Empty: