ChaptersEventsBlog
How is your organization adopting AI technologies? Take this short survey to help us identify key trends and risks across FSI →

Download Publication

Cloud Penetration Testing Playbook
Cloud Penetration Testing Playbook

Cloud Penetration Testing Playbook

Release Date: 07/12/2019

Working Group: Top Threats

As cloud services continue to enable new technologies and see massive adoption there is a need to extend the scope of penetration testing into public cloud systems and components. The process described here aims to provide the foundation for a public cloud penetration testing methodology and is designed for current and future technologies that are hosted on public cloud environments or services. In particular, this document focuses on penetration testing of applications and services hosted in the cloud. It addresses the methodological and knowledge gaps in security testing of information systems and applications in public cloud environments.

This work focuses on testing systems and services hosted in public cloud environments. This refers to customer-controlled or customer-managed systems and services. For example, a custom virtual machine, managed and controlled by the cloud customer, in an IaaS environment would be in-scope whereas the hypervisor of an IaaS environment that is controlled by the cloud service provider isn’t. As for testing hybrid clouds, this document does not cover the hybrid interface and on-premises environment.
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
View translations
Related resources
SCC WG 2026 Charter
SCC WG 2026 Charter
Managing Privileged Access in a Cloud-First World
Managing Privileged Access in a Cloud-First World
Cloud Threat Modeling 2025
Cloud Threat Modeling 2025
Bridging the Gap Between Cloud Security Controls and Adversary Behaviors: A CSA–MITRE Collaboration
Bridging the Gap Between Cloud Security Controls and Adversary Beha...
Published: 02/02/2026
Agentic AI Pen Testing: Speed at Scale, Certainty with Humans
Agentic AI Pen Testing: Speed at Scale, Certainty with Humans
Published: 01/26/2026
My Top 10 Predictions for Agentic AI in 2026
My Top 10 Predictions for Agentic AI in 2026
Published: 01/16/2026
Best Practices to Achieve the Benefits of Agentic AI in Pentesting
Best Practices to Achieve the Benefits of Agentic AI in Pentesting
Published: 01/13/2026

Interested in helping develop research with CSA?

Related Certificates & Training