1. Secure the Primary Identity
Use a unique password and enable multi-factor authentication on the primary or root identity. Protect the email account and phone number used for recovery with MFA as well. Do not reuse credentials from social media, marketplaces or other cloud accounts.
2. Verify Authorized Control
Confirm that account access, contact details, billing information and any transfer arrangement are authorized and allowed by the provider. Review recovery methods and remove unknown contacts. Provider agreements can restrict transfers or resale, so customers must check the current rules before use.
3. Create Separate User Access
Do not use the root or owner identity for routine work. Create separate users or roles and grant only necessary permissions. Prefer temporary credentials and managed identity features over long-lived access keys. Remove inactive users and rotate exposed secrets immediately.
4. Protect API Keys and Secrets
Never place access keys inside public repositories, screenshots, chat messages or client-side website code. Store secrets in a dedicated secret manager or protected environment configuration. Scan repositories and deployment logs for accidental exposure.
5. Configure Billing Alerts
Create budgets and alerts before launching resources. Monitor unexpected compute, storage, bandwidth, AI API and public IP usage. Billing alerts do not automatically stop charges unless you implement a tested control, so review dashboards regularly.
6. Enable Logs and Security Services
Enable the provider's audit logging and retain logs in a protected location. Review sign-ins, permission changes, key creation, new regions and unusual resource launches. Configure security alerts and make sure notifications reach an actively monitored address.
7. Reduce the Attack Surface
- Allow administrative ports only from trusted networks.
- Do not expose databases directly to the public internet.
- Patch operating systems and applications.
- Encrypt sensitive data in transit and at rest.
- Use network segmentation and restrictive firewall rules.
- Back up critical data and test restoration.
8. Prepare an Incident Plan
Document how to revoke credentials, isolate workloads, preserve logs, contact the provider and notify affected parties. If compromise occurs, act quickly: disable exposed keys, reset passwords, review permissions, stop malicious resources and check billing. Do not destroy evidence before understanding the incident.
Monthly Review
Review users, roles, API keys, regions, running resources, storage, backups, budgets and security findings each month. Remove what is no longer needed. Security is an ongoing process rather than a one-time configuration.