Tools and processes that detect cloud misconfigurations and policy drift against best-practice baselines.