AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Use ArnLike instead of StringLike in destination policy example

Service: AmazonCloudWatch · 2026-09-27 · Security-related medium

File: AmazonCloudWatch/latest/logs/CreateDestination.md · Type: iam

Summary

Updates the destination IAM policy example so the aws:SourceArn condition uses the ArnLike operator instead of StringLike.

Security assessment

Switching the aws:SourceArn condition from StringLike to ArnLike makes the sample policy's cross-account authorization check ARN-aware rather than a loose string match, reducing the chance that unintended source ARNs satisfy the condition. This is an IAM authorization hardening in documentation; no specific CVE or incident is cited.

Evidence

+                "ArnLike": {

Diff

diff --git a/AmazonCloudWatch/latest/logs/CreateDestination.md b/AmazonCloudWatch/latest/logs/CreateDestination.md
index b13b3b9ab..8a43ab519 100644
--- a//AmazonCloudWatch/latest/logs/CreateDestination.md
+++ b//AmazonCloudWatch/latest/logs/CreateDestination.md
@@ -61 +61 @@ This policy includes a `aws:SourceArn` global condition context key that specifi
-                "StringLike": {
+                "ArnLike": {