AWS detective: Fix policy documentation URL in security guidance
Summary
Corrected a URL link to the AmazonDetectiveFullAccess policy documentation by removing an extra slash.
Security assessment
The change fixes a broken URL in existing security best practices content but does not introduce new security advice or remediate vulnerabilities.
Evidence
+Limit access to the behavior graph. Users with the [AmazonDetectiveFullAccess](https://docs.aws.amazon.com/detective/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-amazondetectivefullaccess) policy can grant access to all Detective actions. Principals with these permissions can manage member accounts, add tags to their behavior graph, and use Detective for investigation. When a user has access to a behavior graph, they can see all of the findings for the member accounts. Such findings might expose sensitive security information.
Diff
diff --git a/detective/latest/userguide/security-best-practices.md b/detective/latest/userguide/security-best-practices.md index 28325828b..ce6fde31c 100644 --- a//detective/latest/userguide/security-best-practices.md +++ b//detective/latest/userguide/security-best-practices.md @@ -19 +19 @@ When inviting member accounts to your Detective behavior graph, only invite acco -Limit access to the behavior graph. Users with the [AmazonDetectiveFullAccess](https://docs.aws.amazon.com//detective/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-amazondetectivefullaccess) policy can grant access to all Detective actions. Principals with these permissions can manage member accounts, add tags to their behavior graph, and use Detective for investigation. When a user has access to a behavior graph, they can see all of the findings for the member accounts. Such findings might expose sensitive security information. +Limit access to the behavior graph. Users with the [AmazonDetectiveFullAccess](https://docs.aws.amazon.com/detective/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-amazondetectivefullaccess) policy can grant access to all Detective actions. Principals with these permissions can manage member accounts, add tags to their behavior graph, and use Detective for investigation. When a user has access to a behavior graph, they can see all of the findings for the member accounts. Such findings might expose sensitive security information.