Skip to main content
CloudArq
typeindex
scopeaws
topicssecurity · cost
resources · aws · guides

AWS security & cost guides

Hands-on how-tos for the AWS security and cost tasks teams actually get stuck on — each with real console steps, aws-cli commands, and Terraform, plus the CloudArq checks that detect the same issue automatically. Below the guides you'll find the pillar and comparison pages for the whole audit.

Updated 2026-07-20 · read-only · no agents

3
how-to guides
163
checks in the audit
11
pillar deep dives
0
agents installed
how-to guides

Step-by-step AWS guides

Each guide ends by naming the exact CloudArq check IDs that flag the same problem — so you can fix it by hand or let the audit find it across every account.

pillars

Deep dives into the audit

The category, product, and framework pages behind CloudArq's agentless, read-only AWS audit.

compliance mapping

Framework control mappings

CloudArq maps its checks to the technical controls of each framework and shows your posture. It does not certify or guarantee compliance — the mappings are a head start on your own audit.

compare

How CloudArq compares

Honest, complementary framing — AWS-native tools surface signals inside your account; CloudArq is the independent external audit that also hands you the exact fix.

faq

Frequently asked

01What are these guides?
Each guide is a hands-on how-to for one AWS security or cost task — with the exact console clicks, aws-cli commands, and Terraform snippets, plus the CloudArq check IDs that detect the same issue automatically.
02Do I need CloudArq to follow them?
No. Every guide stands on its own with copy-paste AWS steps. CloudArq is the optional shortcut: it runs the same checks read-only across your whole account and hands you the fix, so you do not have to audit resource by resource.
03Is the CloudArq audit read-only?
Yes. CloudArq connects through a read-only IAM role with an ExternalId. It never stores your credentials, application data, database contents, or S3 objects; data is encrypted with AES-256-GCM at rest and hosted in the EU (Helsinki). It detects and gives you the exact remediation steps — it never changes anything in your account.
04How many checks does CloudArq run?
On the Max tier CloudArq runs 192 checks across security, cost, and a dedicated AI-workload lens. Lower tiers run a subset — see the pricing page for what each tier includes.
05Do the compliance guides guarantee compliance?
No. CloudArq maps its checks to the technical controls of frameworks such as SOC 2, ISO 27001, HIPAA, PCI DSS, NIST 800-53, and GDPR, and shows your posture against them. A scanner does not certify or guarantee compliance, and CloudArq the business holds no certifications — the mapping is a starting point for your own audit.
06How do I get started?
Try the interactive demo, or connect an account on the free Starter tier and run your first audit. See the pricing page for tier details.

Skip the manual audit

Every guide here is something CloudArq checks for automatically. Connect a read-only role and the audit runs 192 checks across security, cost, and the AI-workload lens — then groups the gaps and ships each one with a copy-paste CLI or Terraform fix. It detects and gives you the steps; it never changes anything in your account.