Hi everyone. I’ve been tasked with managing cloud security for my organization, but it’s just me handling this for now. We’re in the early stages of migrating some legacy on-prem systems to AWS, with a "lift and shift" approach first.
I’m feeling a bit overwhelmed trying to figure out where to even begin with a tool like Tenable Cloud Security. I know I need visibility into our cloud assets and misconfigurations, but setting up scans and understanding the priorities for a small team seems daunting.
Could anyone share a realistic first-month game plan? Like, what are the absolute first steps after signing up? Should I focus on connecting our AWS accounts first, or is it better to define policies from the get-go? Also, how much daily time should I expect to spend on this initially to get things rolling? 😅
Any step-by-step guidance from those who’ve been in a similar "team of one" spot would be so appreciated. I want to make sure I’m building a solid foundation without missing critical risks during our migration.
One step at a time