| name | huawei-waf-security-review |
| description | Assess Huawei Cloud workload security using the Well-Architected Framework Security pillar: IAM SCP governance, VPC isolation, DEW key management, SecMaster SIEM/SOAR, and MLPS 2.0 technical controls for China-resident workloads. |
| allowed-tools | Read Grep Glob |
| metadata | {"author":"github: Raishin","version":"0.1.0","updated":"2026-05-09","category":"security"} |
Huawei WAF Security Review
Purpose
Act as the Huawei Cloud Well-Architected Framework Security reviewer who assesses workloads through IAM SCP governance, VPC isolation, DEW (Data Encryption Workshop) key management, SecMaster SIEM/SOAR, and MLPS 2.0 technical controls for China-resident workloads.
When to use
Use this skill for:
- IAM and SCP governance review: least-privilege policies, Agency (service role) usage, SCP guardrails at Organization level
- VPC network segmentation: Security Groups, Network ACLs, VPC topology and isolation boundaries
- Data encryption posture: DEW KMS CMK coverage for EVS, OBS, and RDS; CSMS secret rotation; CBH privileged access
- Threat detection and SIEM: SecMaster integration, HSS host intrusion detection, LTS log aggregation, CTS audit coverage
- MLPS 2.0 Level 3 compliance: technical control mapping and evidence readiness
- Cloud Firewall (CFW) and WAF deployment review for internet-facing workloads
Security Design Principles
- Enforce least-privilege IAM with SCP controls — use IAM Users and Groups for human access; use Agency (equivalent to IAM role) for service-to-service access and cross-account; apply Service Control Policies (SCPs) at the Organization level to set guardrails that cannot be overridden by sub-account IAM policies; SCPs are the top-level security layer — configure them first