AWS audit-manager: Revised S3 bucket ownership risk guidance for report destinations
Summary
Replaced explicit warnings about bucket sniping/squatting with emphasis on customer responsibility under the Shared Responsibility Model.
Security assessment
The change removes specific attack vector descriptions (bucket sniping/squatting) but reinforces the security best practice of verifying bucket ownership to prevent unauthorized data access.
Evidence
+Audit Manager publishes your assessment reports to the Amazon S3 bucket that you specify as your assessment report destination. Under the AWS Shared Responsibility Model, you are responsible for confirming that a trusted AWS account owns this bucket. For more information about your security responsibilities, see [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/) on the AWS website.
Diff
diff --git a/audit-manager/latest/userguide/settings-destination.md b/audit-manager/latest/userguide/settings-destination.md index 5ff8b63e1..e856900e9 100644 --- a//audit-manager/latest/userguide/settings-destination.md +++ b//audit-manager/latest/userguide/settings-destination.md @@ -39 +39 @@ If your assessment report destination has a bucket policy that requires server-s -Using a cross-account S3 bucket as your assessment report destination isn’t supported in the Audit Manager console. It’s possible to specify a cross-account bucket as your assessment report destination by using the AWS CLI or one of the AWS SDKs, but for simplicity, we recommend that you not do this. +Using a cross-account S3 bucket as your assessment report destination isn't supported in the Audit Manager console. It's possible to specify a cross-account bucket as your assessment report destination by using the AWS CLI or one of the AWS SDKs, but for simplicity, we recommend that you not do this. @@ -49 +49 @@ If you do choose to use a cross-account S3 bucket as your assessment report dest -Although it’s not a requirement, we recommend that you make the following changes to your cross-account bucket settings. Making these changes ensures that the bucket owner has full control of the assessment reports that you publish to their bucket. +Although it's not a requirement, we recommend that you make the following changes to your cross-account bucket settings. Making these changes ensures that the bucket owner has full control of the assessment reports that you publish to their bucket. @@ -94 +94 @@ JSON -Audit Manager does not validate S3 bucket ownership. This creates a risk if the bucket is deleted and recreated by a different AWS account (known as _bucket sniping_). A risk also exists if an unauthorized party creates a bucket with an anticipated name before you do (known as _bucket squatting_). In either case, Audit Manager continues to publish assessment reports to that bucket. The service does not detect the ownership change. Under the [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/), you are responsible for ensuring that your assessment report destination is a bucket that is owned by a trusted AWS account. +Audit Manager publishes your assessment reports to the Amazon S3 bucket that you specify as your assessment report destination. Under the AWS Shared Responsibility Model, you are responsible for confirming that a trusted AWS account owns this bucket. For more information about your security responsibilities, see [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/) on the AWS website. @@ -138 +138 @@ When you configure Audit Manager to use a customer managed key for data encrypti -S3 buckets created in your account regional namespace include your AWS account ID and AWS Region in the bucket name. These buckets cannot be created by another account, which eliminates the risk of bucket sniping. For more information, see [Account-level bucket namespaces](https://docs.aws.amazon.com/AmazonS3/latest/userguide/gpbucketnamespaces.html#account-regional-gp-buckets) in the _Amazon Simple Storage Service User Guide_. +S3 buckets created in your account regional namespace include your AWS account ID and AWS Region in the bucket name. No other account can create these buckets or claim the bucket name. For more information, see [Account-level bucket namespaces](https://docs.aws.amazon.com/AmazonS3/latest/userguide/gpbucketnamespaces.html#account-regional-gp-buckets) in the _Amazon Simple Storage Service User Guide_. @@ -155 +155 @@ Audit Manager console - 4. When you’re done, choose **Save**. + 4. When you're done, choose **Save**.