AWS Security ChangesHomeSearch

AWS managedservices medium security documentation change

Service: managedservices · 2026-03-25 · Security-related medium

File: managedservices/latest/accelerate-guide/acc-sec-stand-controls.md

Summary

Modified security control 6.11 to allow cross-account policies with write access to third-party accounts if risk acceptance is obtained, changing from an absolute prohibition to a conditional allowance.

Security assessment

This change directly modifies a security control (AMS-STD-002 Point 6.11) regarding cross-account access policies. The relaxation from 'must not be configured' to 'must not be configured without risk acceptance' indicates a policy change that could impact security posture by allowing previously prohibited configurations under specific conditions. This represents a security policy adjustment with potential implications for data access controls.

Diff

diff --git a/managedservices/latest/accelerate-guide/acc-sec-stand-controls.md b/managedservices/latest/accelerate-guide/acc-sec-stand-controls.md
index abea1dcf7..9015f2185 100644
--- a//managedservices/latest/accelerate-guide/acc-sec-stand-controls.md
+++ b//managedservices/latest/accelerate-guide/acc-sec-stand-controls.md
@@ -51 +51 @@ ID | Technical standard
-6.11 | Cross-account policies to access any S3 bucket data or resources where data can be stored (such as Amazon RDS, Amazon DynamoDB, or Amazon Redshift) in a third-party account from an AMS account with write access must not be configured.  
+6.11 | Cross-account policies to access any S3 bucket data or resources where data can be stored (such as Amazon RDS, Amazon DynamoDB, or Amazon Redshift) in a third-party account from an AMS account with write access must not be configured without risk acceptance.