Evaluates whether custom Object Storage Service (OSS) bucket policies contain parameter-specified authorization content. If the policies do not contain such content, the resource is evaluated as compliant.
Scenarios
In enterprise data security management, excluding parameter-specified authorization content from OSS bucket policies helps prevent unauthorized access to sensitive data and enforces the principle of least privilege.
Risk level
Default risk level: medium.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
If custom OSS bucket policies do not contain parameter-specified authorization content, the resource is evaluated as compliant.
Rule details
|
Parameter |
Description |
|
Rule template name |
oss-policy-no-has-specified-document |
|
Rule template identifier |
|
|
Automatic remediation |
Not supported |
|
Trigger type |
Configuration change |
|
Supported resource type |
ACS::OSS::Bucket |
|
Input parameter |
principal, resource, effect, and action |
Non-compliance remediation
If OSS bucket policies do not contain parameter-specified authorization content that references non-compliant resources, see Bucket Policy for remediation steps.