This rule evaluates whether an OSS bucket grants authorizations to accounts outside your resource directory through its bucket policy. A bucket is compliant if public-read access is disabled and all authorizations are within the organization. A bucket is non-compliant if its bucket policy cannot be analyzed or if any authorization is granted to an account outside the resource directory.
Risk level
Default risk level: Medium.
You can change the risk level of this rule as needed.
Detection logic
-
An OSS bucket is compliant if public-read access is disabled and all authorizations in the bucket policy are for accounts within your resource directory. A bucket is non-compliant if its bucket policy cannot be analyzed or if any authorization is granted to an account outside the resource directory.
Rule details
|
Parameter |
Description |
|
Rule name |
Check for authorizations outside the organization in bucket policies |
|
Rule identifier |
|
|
Tag |
OSS |
|
Automatic remediation |
Not supported |
|
Rule trigger |
Configuration change |
|
Supported resource types |
ACS::OSS::Bucket |
|
Input parameters |
None |
Remediation guide
To fix a non-compliant resource, see Overview of permissions and access control.