AWS config medium security documentation change
Summary
Added an entry for 'Security IAM updates' stating that AWS Config managed policies now grant additional permissions for various services.
Security assessment
The change explicitly documents an update to IAM policies (AWSConfigServiceRolePolicy and AWS_ConfigRole) to include new permissions for multiple services. This is a security-related documentation update as it informs users about changes in permissions that could affect access control and security posture. The entry is labeled 'Security IAM updates', indicating it's security-focused.
Diff
diff --git a/config/latest/developerguide/DocumentHistory.md b/config/latest/developerguide/DocumentHistory.md index af1a65792..15642b150 100644 --- a//config/latest/developerguide/DocumentHistory.md +++ b//config/latest/developerguide/DocumentHistory.md @@ -39,0 +40 @@ AWS Config supports new conformance packs| With this release, AWS Config support +Security IAM updates| The `AWSConfigServiceRolePolicy` and `AWS_ConfigRole` policies now grant additional permissions for auditmanager, bcm-dashboards, bedrock, bedrock-agentcore, chime, dms, emr-containers, gameliftstreams, globalaccelerator, glue, lambda, medialive, mediapackagev2, outposts, qbusiness, redshift, rtbfabric, s3express, s3vectors, sagemaker, servicecatalog, ssm-contacts, ssm-guiconnect, sso, textract, transfer, and wisdom services. For more information, see [AWS managed policies for AWS Config](https://docs.aws.amazon.com/config/latest/developerguide/security-iam-awsmanpol.html).| March 10, 2026 @@ -2109 +2110 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -PutDeliveryChannel +Getting started with Config