---
title: "cloud-security"
author: "Mohammad Abu Mattar"
canonical: https://mkabumattar.com/blog/tags/cloud-security
---

[All Tags](/blog/tags)

# #Cloud security

[Home](/)›[All Posts](/blog)›[All Tags](/blog/tags)›[Cloud security](/blog/tags/cloud-security)

Tag

# #Cloud security

[![Compliance as Code: Making Security Easier with Terraform and InSpec](/_astro/hero.CuKP9d1A_ZJUUcq.webp)](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)

## [Compliance as Code: Making Security Easier with Terraform and InSpec](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Compliance as Code](/blog/categories/compliance-as-code)
-   [Security](/blog/categories/security)
-   [DevSecOps](/blog/categories/devsecops)
-   [Terraform](/blog/categories/terraform)
-   [InSpec](/blog/categories/inspec)
-   [Cloud](/blog/categories/cloud)
-   [Governance](/blog/categories/governance)
-   Published: 03 Aug, 2025

Hey, so you know how keeping our tech stuff secure and following all the rules can be a real headache these days? With everything moving to the cloud and so many regulations popping up, it's tough to

[#Compliance](/blog/tags/compliance)[#NIST](/blog/tags/nist)[#ISO 27001](/blog/tags/iso-27001)+7 tags

[read more](/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec)

[![Unlocking the Secrets: HashiCorp Vault vs. AWS Secrets Manager vs. SOPS - Which Reigns Supreme](/_astro/hero.BxpvzHJN_Z2hLAEl.webp)](/blog/post/secrets-management-vault-secrets-manager-sops)

## [Unlocking the Secrets: HashiCorp Vault vs. AWS Secrets Manager vs. SOPS - Which Reigns Supreme](/blog/post/secrets-management-vault-secrets-manager-sops)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [DevOps](/blog/categories/devops)
-   [Security](/blog/categories/security)
-   [Cloud Computing](/blog/categories/cloud-computing)
-   Published: 25 May, 2025

Let's face it, in today's tech world, keeping sensitive info safe – we're talking about those digital keys like API keys and passwords – is a big deal. They're what let you into important systems and

[#Secrets Management](/blog/tags/secrets-management)[#HashiCorp Vault](/blog/tags/hashicorp-vault)[#AWS Secrets Manager](/blog/tags/aws-secrets-manager)+4 tags

[read more](/blog/post/secrets-management-vault-secrets-manager-sops)

[![Navigating Growth: Building a Secure and Scalable AWS Environment with a Multi-Account Architecture and Control Tower](/_astro/hero.BShn8B1r_Zu8h2W.webp)](/blog/post/multi-account-aws-control-tower)

## [Navigating Growth: Building a Secure and Scalable AWS Environment with a Multi-Account Architecture and Control Tower](/blog/post/multi-account-aws-control-tower)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Cloud Computing](/blog/categories/cloud-computing)
-   [AWS](/blog/categories/aws)
-   [DevOps](/blog/categories/devops)
-   [Cloud Security](/blog/categories/cloud-security)
-   [Cloud Architecture](/blog/categories/cloud-architecture)
-   Published: 13 Apr, 2025

The cloud journey often kicks off with a single AWS account – it feels simple and straightforward, especially when you're just starting out or have smaller teams. But as your cloud usage grows, that i

[#AWS](/blog/tags/aws)[#Control Tower](/blog/tags/control-tower)[#Multi Account Strategy](/blog/tags/multi-account-strategy)+8 tags

[read more](/blog/post/multi-account-aws-control-tower)

[![Policy as Code with Open Policy Agent: A Technical and Governance Perspective](/_astro/hero.FMyPom55_ZBRCR.webp)](/blog/post/policy-as-code-opa-guide)

## [Policy as Code with Open Policy Agent: A Technical and Governance Perspective](/blog/post/policy-as-code-opa-guide)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [DevOps](/blog/categories/devops)
-   [Security](/blog/categories/security)
-   [Cloud Governance](/blog/categories/cloud-governance)
-   [Policy as Code](/blog/categories/policy-as-code)
-   Published: 08 Apr, 2025

Think about how much stuff modern organizations have running in the cloud these days. It's a lot, right? All those servers, applications, and connections can get pretty complicated to manage. Just cli

[#Open Policy Agent](/blog/tags/open-policy-agent)[#OPA](/blog/tags/opa)[#Policy as Code](/blog/tags/policy-as-code)+9 tags

[read more](/blog/post/policy-as-code-opa-guide)

[![Zero Trust Architecture in DevOps Pipelines: Secure Your CI/CD Workflows](/_astro/hero.BrNMLyL7_1lCSFT.webp)](/blog/post/zero-trust-devops-pipelines-securing-ci-cd)

## [Zero Trust Architecture in DevOps Pipelines: Secure Your CI/CD Workflows](/blog/post/zero-trust-devops-pipelines-securing-ci-cd)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [DevOps](/blog/categories/devops)
-   [Cloud Security](/blog/categories/cloud-security)
-   [Zero Trust Architecture](/blog/categories/zero-trust-architecture)
-   [CI/CD](/blog/categories/cicd)
-   Published: 05 Apr, 2025

In today's rapidly evolving digital landscape, security is paramount especially in DevOps environments where CI/CD pipelines and cloud infrastructure drive software delivery. One paradigm that’s resha

[#Zero Trust](/blog/tags/zero-trust)[#DevOps](/blog/tags/devops)[#CI/CD Security](/blog/tags/cicd-security)+7 tags

[read more](/blog/post/zero-trust-devops-pipelines-securing-ci-cd)

[![Unleashing the Magic: Best Practices for Infrastructure Automation in a Cloud Native AWS Environment](/_astro/hero.CTyi0Kde_16WUz4.webp)](/blog/post/unleashing-the-magic-best-practices-for-infrastructure-automation-in-a-cloud-native-aws-environment)

## [Unleashing the Magic: Best Practices for Infrastructure Automation in a Cloud Native AWS Environment](/blog/post/unleashing-the-magic-best-practices-for-infrastructure-automation-in-a-cloud-native-aws-environment)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [AWS](/blog/categories/aws)
-   [Cloud Native](/blog/categories/cloud-native)
-   [DevOps](/blog/categories/devops)
-   [Infrastructure Automation](/blog/categories/infrastructure-automation)
-   [Best Practices](/blog/categories/best-practices)
-   Published: 22 May, 2023

Introduction: In the realm of Cloud Native AWS environments, mastering infrastructure automation is essential to unlock the full potential of your magical kingdom. From security spells to optimizi

[#AWS Automation](/blog/tags/aws-automation)[#Infrastructure as Code (IaC)](/blog/tags/infrastructure-as-code-iac)[#CI/CD Pipelines](/blog/tags/cicd-pipelines)+7 tags

[read more](/blog/post/unleashing-the-magic-best-practices-for-infrastructure-automation-in-a-cloud-native-aws-environment)

[![How to Avoid Common Cloud Services Mistakes](/_astro/hero.9gb_YEzv_5JpIH.webp)](/blog/post/how-to-avoid-common-cloud-services-mistakes)

## [How to Avoid Common Cloud Services Mistakes](/blog/post/how-to-avoid-common-cloud-services-mistakes)

-   [Mohammad Abu Mattar](/authors/mohammad-abu-mattar)
-   [Cloud Strategy](/blog/categories/cloud-strategy)
-   [AWS](/blog/categories/aws)
-   [Cloud Security](/blog/categories/cloud-security)
-   [Cost Management](/blog/categories/cost-management)
-   [DevOps](/blog/categories/devops)
-   Published: 20 Jan, 2023

Introduction By offering scalable, on-demand resources and services, cloud services have completely changed the way organizations operate. Implementing cloud services, however, can provide its own

[#Cloud Mistakes](/blog/tags/cloud-mistakes)[#AWS Best Practices](/blog/tags/aws-best-practices)[#Cloud Security](/blog/tags/cloud-security)+6 tags

[read more](/blog/post/how-to-avoid-common-cloud-services-mistakes)
