All Products
Search
Document Center

Cloud Config:Check for authorizations outside the organization in bucket policies

Last Updated:Jun 23, 2026

This rule evaluates whether an OSS bucket grants authorizations to accounts outside your resource directory through its bucket policy. A bucket is compliant if public-read access is disabled and all authorizations are within the organization. A bucket is non-compliant if its bucket policy cannot be analyzed or if any authorization is granted to an account outside the resource directory.

Risk level

Default risk level: Medium.

You can change the risk level of this rule as needed.

Detection logic

  • An OSS bucket is compliant if public-read access is disabled and all authorizations in the bucket policy are for accounts within your resource directory. A bucket is non-compliant if its bucket policy cannot be analyzed or if any authorization is granted to an account outside the resource directory.

Rule details

Parameter

Description

Rule name

Check for authorizations outside the organization in bucket policies

Rule identifier

oss-bucket-policy-outside-organization-check

Tag

OSS

Automatic remediation

Not supported

Rule trigger

Configuration change

Supported resource types

ACS::OSS::Bucket

Input parameters

None

Remediation guide

To fix a non-compliant resource, see Overview of permissions and access control.