AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Add aws:SourceAccount condition to SQS resource policy

Service: AmazonCloudWatch · 2026-09-27 · Documentation medium

File: AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md · Type: iam

Summary

Extends the SQS queue resource policy example with a StringEquals aws:SourceAccount condition alongside the existing aws:SourceArn restriction.

Security assessment

Adding aws:SourceAccount to the SQS policy limits which account's S3 events can send notifications, a standard confused-deputy mitigation that hardens the resource policy.

Evidence

+                "StringEquals": {"aws:SourceAccount": "<account-id>"}

Diff

diff --git a/AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md b/AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md
index e2d2afe68..567f13b8f 100644
--- a//AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md
+++ b//AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md
@@ -76 +76,2 @@ Add a resource policy to the Amazon SQS queue allowing Amazon S3 to send event n
-                "ArnEquals": {"aws:SourceArn": "arn:aws:s3:::<bucket-name>"}
+                "ArnEquals": {"aws:SourceArn": "arn:aws:s3:::<bucket-name>"},
+                "StringEquals": {"aws:SourceAccount": "<account-id>"}