Hackfest - Level UP

Cloud Security Posture Management (CSPM) on a Shoestring
Language: English

CSPM is just a marketing term for configuration management aligned to standards-based controls validation of security baselines. As a result of the marketing hype, CSPM toolsets are often unreasonably priced, are limited in controls, scope, or flexibility.

We will explore the multitude of freely available tools for validation of various perspectives, align them to industry standard baselines such as those provided by CIS, CISA, ASD, and others against Microsoft cloud environments and discuss where they overlap or fail.

Attendees will leave with a toolkit of options based on real life testing in an enterprise environment. This will cover configuration drift, prioritise misconfigurations based on risk, options to automate evidence collection, and reporting without purchasing a dedicated CSPM platform.

Effective posture management is not about buying another dashboard, it is about treating cloud security as disciplined configuration management and continuously verifying that your environment remains aligned with established security baselines.


  • Introduction / Agenda / whomi / Overview - 5 mins
  • Review terms - relate things back to standards and controls validation / config mgmt - 5 mins
  • Discuss defining IT governance as a definition of baseline control standards against organisational risk tolerance.
  • Discuss defining controls validation as opposed to a prize to win for "compliancy" (e.g. SOC2) and that word doesn't mean what you think it means.
  • Review of baseline options for controls validation - where to get best practices - 5 mins
  • CISA, CIS, ASD, STIGs, MS built-in tools, other.
  • Differentiate the scope of each of these and limitations.
  • Review available open source toolsets and complexities / limitations / failures for use - 15 mins
  • Explore automation options for execution, reporting and "continuous" validation (is anything really continuous when it runs at a point in time?) - 5 mins
  • Using modern non-deterministic inference engines to craft standardised risk statements based on the report outputs - 5 mins
  • Closing 5 mins
  • Wrap up / conclusions
  • References
  • Questions - 5 mins
The speaker's profile picture
Don Mallory

Don Mallory has over 30 years of experience in enterprise IT, primarily in critical infrastructure, specializing in operations, data storage, disaster recovery, and security for critical infrastructure. Professionally, Don is a Senior Security Analyst in the healthcare sector. He is a co-author of “Applied Data Security Strategy - A Leader’s Guide”, and has been involved in various volunteer activities including C3X, Hak4Kidz Toronto, and teaching darkroom photography.