Cloud egress
Controlling what workloads are allowed to connect out to is one of the few controls that still works after something is compromised.
Most attacks require a channel back: to fetch tooling, to receive instructions, to send data out. Restricting outbound to what is actually needed breaks that, and it is far less commonly done than inbound filtering because nothing fails visibly when you skip it.
Checked against the primary source.
