AWS AmazonCloudWatch: Add aws:SourceAccount condition to SQS resource policy
Summary
Extends the SQS queue resource policy example with a StringEquals aws:SourceAccount condition alongside the existing aws:SourceArn restriction.
Security assessment
Adding aws:SourceAccount to the SQS policy limits which account's S3 events can send notifications, a standard confused-deputy mitigation that hardens the resource policy.
Evidence
+ "StringEquals": {"aws:SourceAccount": "<account-id>"}
Diff
diff --git a/AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md b/AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md index e2d2afe68..567f13b8f 100644 --- a//AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md +++ b//AmazonCloudWatch/latest/monitoring/cisco-ftd-source-config.md @@ -76 +76,2 @@ Add a resource policy to the Amazon SQS queue allowing Amazon S3 to send event n - "ArnEquals": {"aws:SourceArn": "arn:aws:s3:::<bucket-name>"} + "ArnEquals": {"aws:SourceArn": "arn:aws:s3:::<bucket-name>"}, + "StringEquals": {"aws:SourceAccount": "<account-id>"}