Cloud posture controls do not replace access reviews because they evaluate configuration and exposure, not business justification for access. A resource can be fully monitored and still have stale admins, shared accounts, or over-scoped app permissions. Access reviews remain necessary to validate who should keep access and why.
Why cloud posture controls and access reviews solve different problems
Cloud posture controls and access reviews answer different questions. Posture controls tell you whether a cloud account, subscription, project, or workload is configured safely; access reviews tell you whether a person, service, or admin should still have that access at all. A strong posture does not prove the current access map is justified, current, or aligned to business need.
That distinction matters because posture tools are mostly about exposure, configuration drift, and policy compliance. Access reviews are about entitlement validity, ownership, and accountability. You can have clean encryption, logging, and network segmentation while still carrying dormant admins, shared accounts, stale break-glass access, or application permissions that nobody can explain.
What posture tools can see, and what they miss
Cloud posture controls are good at spotting weak defaults, broad permissions, public exposure, missing logging, insecure storage settings, and other misconfigurations. They are also useful for trend reporting, drift detection, and prioritising remediation when the cloud environment itself has become too permissive or too exposed.
What they do not do well is decide whether access is still legitimate. A posture engine can flag that an IAM role is overbroad, but it cannot tell you whether the role owner changed teams, whether the app was retired, whether a contractor left, or whether a human is still using a shared credential. That requires Access Reviews and Certification Guide style governance, not just configuration monitoring.
For cloud environments, this is why posture and lifecycle controls need to work together. Cloud PAM and CIEM Guide is useful where the question is effective cloud privilege, while Identity Security Posture Management (ISPM) Guide helps teams connect posture findings to standing access, stale identities, and privilege hygiene.
Why stale access survives even in well-monitored cloud estates
Cloud posture programs often operate at the resource layer, so they can miss the human and operational context behind an entitlement. That is why a tenant can look well governed on paper while still accumulating unused admin roles, inherited permissions, service accounts with no clear owner, and access that was granted for a one-time project but never revoked.
Access reviews close that gap by forcing an explicit decision: keep, reduce, transfer, or remove. They are the control that tests whether the access model still matches reality. This is also where IAM and IGA Basics becomes relevant, because cloud posture alone does not replace identity governance, entitlement ownership, or recertification discipline.
In practice, the most persistent failure mode is assuming that continuous monitoring equals continuous authorisation. Monitoring can show that access is being used; it does not show that the access should exist. The answer to that question must come from periodic certification, ownership checks, and cleanup of accounts and roles that have outlived their purpose.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud posture and access review questions both hinge on cloud identity and entitlement governance. |
| Recommendation — Map cloud entitlement drift to IAM controls and review who should keep each permission. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews test whether cloud accounts and roles still need their current access. |
| IA-5 — Authenticator Management | Shared accounts and stale credentials are part of the access-review gap posture tools miss. | |
| Recommendation — Review cloud accounts periodically and remove access that no longer has business justification. Rotate or revoke unused authenticators and validate that only current owners retain them. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The distinction between configuration posture and access legitimacy sits inside access-control governance. |
| Recommendation — Apply access-control reviews to confirm that cloud permissions remain necessary and approved. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Cloud posture does not replace periodic validation of account and privilege assignments. |
| Recommendation — Enforce periodic access reviews for cloud accounts, roles, and privileged permissions. | ||
Practitioner Guidance
What to prioritise: Treat posture findings as a trigger for review, not as evidence of approval. If a cloud role, group, or service account is flagged as broad or dormant, the next step is to confirm ownership and business need, not to assume the finding is acceptable because the environment is monitored.
What to verify: Verify that every high-impact cloud entitlement has a named owner, a current purpose, and a review path. If you cannot identify who can vouch for the access, that is a stronger governance problem than a configuration issue.
Common mistake: Teams often use posture dashboards as a proxy for access governance. That shortcut misses stale admins, inherited roles, shared accounts, and permissions granted outside the normal joiner-mover-leaver flow.
Practitioner takeaway: Use cloud posture to reduce exposure, but use access reviews to prove legitimacy. One control tells you the environment is safer; the other tells you the access is still justified.