🛡 CLOUD SECURITY • CNAPP • MULTI-CLOUD

Enterprise Cloud Security with Wiz CNAPP

A sanitized portfolio case study exploring how Wiz CNAPP can help security teams discover, correlate and prioritize cloud risks across AWS, Microsoft Azure and Google Cloud.

Wiz CNAPP CSPM CIEM AWS Azure Google Cloud IAM Vulnerability Management
Independent & Sanitized Portfolio Case Study

This reference architecture is independently created to demonstrate cloud-security concepts and Wiz CNAPP workflows. It contains no client information, employer architecture, proprietary code, account details or confidential security findings.

01 • THE PROBLEM

Securing a Large Multi-Cloud Environment

Imagine an enterprise operating dozens of AWS accounts, Microsoft Azure subscriptions and Google Cloud projects. Thousands of cloud resources are continuously created, modified and removed by different engineering teams.

Security teams need visibility into questions such as:

🌐 Which workloads are exposed to the internet?
🐞 Which systems contain critical vulnerabilities?
🔑 Which identities have excessive permissions?
🗄 Which resources can access sensitive data?
⚠️ Which cloud configurations create security risk?
🎯 Which findings should security teams fix first?
02 • THE PLATFORM

What is Wiz CNAPP?

Wiz is a Cloud Native Application Protection Platform (CNAPP) that provides security visibility across cloud environments.

Instead of looking at vulnerabilities, identities, configurations and exposure completely independently, contextual cloud-security analysis can help security teams understand how multiple risks may combine into a more significant attack path.

☁️ CSPM

Cloud configuration and security posture visibility.

🔑 CIEM

Cloud identity, permissions and entitlement risk.

🐞 Vulnerabilities

Workload and software vulnerability visibility.

🎯 Attack Paths

Understanding combinations of risks and exposure.

03 • ARCHITECTURE

Conceptual Multi-Cloud Architecture

The following simplified architecture represents a fictional enterprise connecting multiple cloud environments to a centralized cloud-security platform.

                    ENTERPRISE CLOUD

        AWS              AZURE               GCP
         │                 │                  │
   Organizations      Subscriptions        Projects
         │                 │                  │
   EC2 • S3 • IAM     VM • Storage       GCE • GCS
   EKS • RDS          AKS • SQL          GKE • SQL
         │                 │                  │
         └─────────────────┼──────────────────┘
                           │
                           ▼
                       WIZ CNAPP
                           │
        ┌──────────────────┼──────────────────┐
        ▼                  ▼                  ▼
       CSPM               CIEM        Vulnerabilities
        │                  │                  │
        └──────────────────┼──────────────────┘
                           ▼
                   Security Context
                           │
                           ▼
                  Attack Path Analysis
                           │
                           ▼
                   Risk Prioritization
                           │
                           ▼
                      Remediation
04 • SECURITY WORKFLOW

How I Approach Wiz Cloud Security

Cloud Onboarding Asset Visibility Security Findings Risk Context Investigation Remediation
05 • INVESTIGATION SCENARIO

From Individual Findings to an Attack Path

A vulnerability by itself may not always represent the organization's highest-priority risk. Context changes the security picture.

Consider this fictional scenario:

🌐 Internet Exposure Publicly reachable workload
🐞 Critical Vulnerability Exploitable software weakness
🔑 Powerful IAM Role Excessive cloud permissions
🗄 Sensitive Data Access Access to a critical data resource
Security Insight

Looking at these findings independently may create four separate alerts. Looking at them together reveals a potential path from internet exposure to sensitive data. This context helps security teams prioritize remediation.

06 • SKILLS DEMONSTRATED

Cloud Security Capabilities

Wiz CNAPP Administration
Cloud Security Posture Management
Identity & Permission Risk
Vulnerability Management
Attack Path Investigation
Multi-Cloud Security
Risk Prioritization
Security Remediation
Next: Technical Deep Dive

This case study will be expanded with detailed sections covering cloud onboarding, CSPM findings, IAM/CIEM analysis, vulnerability investigation, Kubernetes security, compliance and remediation workflows.