Every cloud security tool derives its checks from published knowledge. CIS benchmarks, best practices and advisories. But the configuration surface is determined by what the service allows, not by what researchers have discovered. The gap between those two sets is where breaches happen.