AWS Security ChangesHomeSearch

AWS govcloud-us medium security documentation change

Service: govcloud-us · 2026-05-01 · Security-related medium

File: govcloud-us/latest/UserGuide/history.md

Summary

Added two history entries: Amazon RDS for Db2 availability in GovCloud and GuardDuty policy deprecation/replacement with scoped-down policy.

Security assessment

The GuardDuty policy change specifically deprecates the AmazonGuardDutyFullAccess policy and replaces it with a scoped-down policy (AmazonGuardDutyFullAccess_v2). This indicates a security improvement to follow least privilege principles, potentially addressing over-permissive access issues. The explicit mention of policy deprecation and replacement with a more restrictive policy suggests security hardening.

Diff

diff --git a/govcloud-us/latest/UserGuide/history.md b/govcloud-us/latest/UserGuide/history.md
index 57b099a07..e87f5dcb1 100644
--- a//govcloud-us/latest/UserGuide/history.md
+++ b//govcloud-us/latest/UserGuide/history.md
@@ -12,0 +13,2 @@ Change| Description| Date
+Amazon RDS for Db2| Amazon RDS for Db2 is now available in AWS GovCloud (US) Regions with Bring Your Own License (BYOL).| April 29, 2026  
+[Amazon GuardDuty](./govcloud-guardduty.html)|  GuardDuty has deprecated the `AmazonGuardDutyFullAccess` policy and replaced it with a scoped-down policy named `AmazonGuardDutyFullAccess_v2`. For more information, see [AWS managed policy: AmazonGuardDutyFullAccess_v2](https://docs.aws.amazon.com/guardduty/latest/ug/security-iam-awsmanpol.html#security-iam-awsmanpol-AmazonGuardDutyFullAccess-v2).| March 13, 2026