AWS managedservices medium security documentation change
Summary
Modified security control 6.11 to allow cross-account policies with write access to third-party accounts if risk acceptance is obtained, changing from an absolute prohibition to a conditional allowance.
Security assessment
This change directly modifies a security control (AMS-STD-002 Point 6.11) regarding cross-account access policies. The relaxation from 'must not be configured' to 'must not be configured without risk acceptance' indicates a policy change that could impact security posture by allowing previously prohibited configurations under specific conditions. This represents a security policy adjustment with potential implications for data access controls.
Diff
diff --git a/managedservices/latest/accelerate-guide/acc-sec-stand-controls.md b/managedservices/latest/accelerate-guide/acc-sec-stand-controls.md index abea1dcf7..9015f2185 100644 --- a//managedservices/latest/accelerate-guide/acc-sec-stand-controls.md +++ b//managedservices/latest/accelerate-guide/acc-sec-stand-controls.md @@ -51 +51 @@ ID | Technical standard -6.11 | Cross-account policies to access any S3 bucket data or resources where data can be stored (such as Amazon RDS, Amazon DynamoDB, or Amazon Redshift) in a third-party account from an AMS account with write access must not be configured. +6.11 | Cross-account policies to access any S3 bucket data or resources where data can be stored (such as Amazon RDS, Amazon DynamoDB, or Amazon Redshift) in a third-party account from an AMS account with write access must not be configured without risk acceptance.