Skip to main content

πŸ’Ό [S3.6] S3 general purpose bucket policies should restrict access to other AWS accounts

  • Contextual name: πŸ’Ό [S3.6] S3 general purpose bucket policies should restrict access to other AWS accounts

  • ID: /frameworks/aws-fsbp-v1.0.0/s3/06

  • Located in: πŸ’Ό Simple Storage Service (S3)

Description​

Implementing least privilege access is fundamental to reducing security risk and the impact of errors or malicious intent. If an S3 bucket policy allows access from external accounts, it could result in data exfiltration by an insider threat or an attacker.

The blacklistedactionpatterns parameter allows for successful evaluation of the rule for S3 buckets. The parameter grants access to external accounts for action patterns that are not included in the blacklistedactionpatterns list.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags