Next-Generation Database Hardening and Threat Visibility Framework for Hybrid AWS-Azure Clouds with Wiz Analytics

Authors

  • Nareddy Abhireddy Author

DOI:

https://doi.org/10.5281/zenodo.20443447

Keywords:

: Cloud-integrated database security,Hybrid cloud security architecture,AWS–Azure hybrid environments,Database hardening framework,Cloud security posture management (CSPM),Automated security posture assessment,Wiz security insights,Multi-cloud risk visibility,Cloud-native database protection,Zero trust data security,Security posture automation,Misconfiguration detection in cloud databases,Compliance monitoring in hybrid clouds,Continuous security assurance,Cloud attack surface management,Identity and access management for databases,Infrastructure-as-code security validation,Threat modeling for hybrid databases,Cross-cloud governance and controls,DevSecOps-driven database security

Abstract

Cloud services allow enterprises to establish hybrid, multi-cloud environments. Such proliferation increases complexity and the attack surface, leading to needed security-, privacy-, and accessibility-compliance controls. Existing tools underutilize cloud providers’ compliance tools. Wiz automates asset inventory, vulnerability management, compliance drift detection, risk insights, and identity and access management. Cloud-integrated database hardening uses Wiz insights and guidance to automate hardening and compliance in heterogeneous clouds. Assets—data stores, storage accounts, and databases—proliferate in Azure and AWS, often within a single logical entity. A framework automates security posture, improving cloud-integrated database hardening in hybrid AWS–Azure environments. Data collection and telemetry follow Wiz-driven insights. Controls satisfy technical risks for hybrid asset-sharing scenarios. Attack surfaces and risks in heterogeneous AWS–Azure environments are specified and mitigated. Security controls are mapped to family and subfamily participants. Identity and access management splits responsibilities between Azure and AWS security flaws. Database service encryption meets Azure Secrets store and KMS risk categories.

The threat landscape of hybrid solutions is broader than that of single- or multi-cloud deployments. Data-exfiltration-database-leaking-risk scenarios for Azure are addressed by Wiz identity and access management recommendations and Microsoft and AWS database-service data-in-transit-and-at-rest-encryption controls. These recommendations automate security-compliance attestation. Azure data resource characteristics and Wiz approach are combined with risk categories for remaining clouds. A simple security-architecture pattern for control-expression mapping creates the required hardening.

References

[1] Ali, S. (2025). Role of automation in hybrid cloud security configuration management. ResearchGate Preprint.

[2] Amazon Web Services. (2025). Analyze Azure audit logs with CloudTrail Lake (AWS Blog). Amazon Web Services.

[3] Amazon Web Services. (2025). Strategy guidance: Creating a single hybrid and multicloud technology and governance strategy (AWS Prescriptive Guidance). Amazon Web Services.

[4] Amazon Web Services. (2024). Improving overall security posture with Wiz: Secured AWS landing zone (AWS Partner Network Blog). Amazon Web Services.

[5] ANSSI. (2025). Technical position paper on confidential computing (CoCo), v1.0. Agence nationale de la sécurité des systèmes d’information.

[6] Bertani, A., et al. (2025). Confidential computing: A security overview and future perspectives. CEUR Workshop Proceedings.

[7] Center for Internet Security. (2024). CIS Microsoft Azure Foundations Benchmark (v2.0.0). Center for Internet Security.

[8] Center for Internet Security. (2023). CIS Amazon Web Services Foundations Benchmark (v1.5.0). Center for Internet Security.

[9] Center for Internet Security. (2024). CIS Microsoft Azure Database Services Benchmark (v1.0.0). Center for Internet Security.

[10] Center for Internet Security. (2024). CIS Microsoft Azure Compute Services Benchmark (v2.0.0). Center for Internet Security.

[11] Cloud Security Alliance. (2024). Cloud Controls Matrix (CCM) and CAIQ v4. Cloud Security Alliance.

[12] Cloud Security Alliance. (2017). Security guidance for critical areas of focus in cloud computing (v4.0). Cloud Security Alliance.

[13] Confidential Computing Consortium. (2023). A technical analysis of confidential computing (v1.3). Confidential Computing Consortium.

[14] Feng, D. (2024). Survey of research on confidential computing. IET Cyber-Physical Systems: Theory & Applications.

[15] Force, J. T., et al. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53 Rev. 5). National Institute of Standards and Technology.

[16] Huang, J., & Yi, J. (2024). The key security management scheme of cloud storage based on blockchain and digital twins. Journal of Cloud Computing, 13, Article 15.

[17] International Organization for Standardization. (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. ISO.

[18] International Organization for Standardization. (2015). ISO/IEC 27017:2015: Code of practice for information security controls based on ISO/IEC 27002 for cloud services. ISO.

[19] International Organization for Standardization. (2019). ISO/IEC 27018:2019: Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors. ISO.

[20] Liu, J., et al. (2024). Key-aggregate based access control encryption for flexible authorization and efficient sharing. Computer Communications.

[21] Mani, A. (2024). Cryptography in the cloud: Securing cloud data with encryption. International Journal of Electronic Security and Digital Forensics.

[22] Microsoft. (2025). Cloud infrastructure entitlement management (CIEM) in Defender for Cloud. Microsoft Learn.

[23] Microsoft. (2025). Azure security logging and auditing. Microsoft Learn.

[24] Microsoft. (2024). CIS Microsoft Azure Foundations Benchmark 2.0.0 mapping (Azure Policy Regulatory Compliance initiative). Microsoft Learn.

[25] MITRE. (2024). MITRE ATTACK Cloud Matrix (Enterprise). MITRE.

[26] Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of zero trust architecture across domains. Sensors, 25(19), 6118.

[27] National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). NIST.

[28] National Institute of Standards and Technology. (2020). Zero trust architecture (NIST SP 800-207). NIST.

[29] National Institute of Standards and Technology. (2022). Secure software development framework (SSDF) version 1.1 (NIST SP 800-218). NIST.

[30] Pahl, C. (2025). Infrastructure as code: Technology review and research challenges. Proceedings (SciTePress).

[31] Souppaya, M., Scarfone, K., & Dodson, D. (2022). Secure software development framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (NIST SP 800-218). National Institute of Standards and Technology.

[32] Verdet, A. (2023). Exploring security practices in infrastructure as code: An empirical study (Master’s thesis). Polytechnique Montréal.

Additional Files

Published

2026-05-23

Data Availability Statement

None

How to Cite

Next-Generation Database Hardening and Threat Visibility Framework for Hybrid AWS-Azure Clouds with Wiz Analytics. (2026). European Advanced Journal for Science & Engineering (EAJSE) -P-ISSN 3050-9696 En E-ISSN 3050-970X, 3(03). https://doi.org/10.5281/zenodo.20443447