All Products
Search
Document Center

Cloud Config:oss-policy-no-has-specified-document

Last Updated:Jun 17, 2026

Evaluates whether custom Object Storage Service (OSS) bucket policies contain parameter-specified authorization content. If the policies do not contain such content, the resource is evaluated as compliant.

Scenarios

In enterprise data security management, excluding parameter-specified authorization content from OSS bucket policies helps prevent unauthorized access to sensitive data and enforces the principle of least privilege.

Risk level

Default risk level: medium.

You can change the risk level based on your business requirements when you apply this rule.

Compliance evaluation logic

If custom OSS bucket policies do not contain parameter-specified authorization content, the resource is evaluated as compliant.

Rule details

Parameter

Description

Rule template name

oss-policy-no-has-specified-document

Rule template identifier

oss-policy-no-has-specified-document

Automatic remediation

Not supported

Trigger type

Configuration change

Supported resource type

ACS::OSS::Bucket

Input parameter

principal, resource, effect, and action

Non-compliance remediation

If OSS bucket policies do not contain parameter-specified authorization content that references non-compliant resources, see Bucket Policy for remediation steps.