Shared Responsibility Model for Abstracted Services

Information

For abstracted services, such as Amazon S3 and Amazon DynamoDB, AWS operates the infrastructure layer, the operating system, and platforms and you access the endpoints to store and retrieve data.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Amazon S3 and DynamoDB are tightly integrated with IAM. You are responsible for managing your data (including classifying your assets), and for using IAM tools to apply ACL-type permissions to individual resources at the platform level, or permissions based on user identity or user responsibility at the IAM user/group level.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|SC-2, 800-53|SC-3, 800-53|SC-7

Plugin: amazon_aws

Control ID: 2a4fa97baf5c56e16a6b775c18c94444f246891233ad1dcba4eb15ed9cc17d24