DRHCSEC04-BP01 Restrict access by location of resource
Specify IAM actions to restrict based on where the resource's storage of data would be located.
Desired outcome: Access management policies allow data storage only in locations that comply with data residency regulations.
Common anti-patterns:
-
Allowing unrestricted access to all resources
-
Allowing the launching of instances in the Region when requirements for a given workload only require launching in an Outpost or Local Zone
-
Allowing creation of roles, users, and attach policies without attaching AWS IAM permission boundaries
Level of risk exposed if this best practice is not established: High
Implementation guidance
-
Analyze location of data in your least privilege access analysis. This requires awareness of the actions that can impact the location of data.
-
If need to allow principals to store data in Amazon S3 on Outposts but not in Region buckets, then deny the
s3:PutObjectaction on the Resourcearn:aws:s3:::*, or only allow the action s3:PutObject on specific S3 buckets using resource values that match the patternarn:aws:s3-outposts:${region}:${account-id}:outpost/outpost-id/accesspoint/${accesspoint-name}. -
Restrict the creation of instances and network interfaces to specific subnets by using policy resources to create a dynamically-composed list of authorized subnets for the following IAM actions:
-
ec2:RunInstances -
ec2:CreateNetworkInterface -
ec2:RequestSpotFleet -
ec2:RequestSpotInstances -
rds:CreateDbSubnet -
elasticache:CreateCacheSubnetGroup -
autoscaling:CreateAutoScalingGroup -
elasticloadbalancing:CreateLoadBalancer -
ec2:CreateLaunchTemplate
-
-
The
ec2:CreateSnapshot*actions should not be allowed to principals that don't need it. For principals that do, you can deny data transfer from an Outpost to a Region by attaching a deny policy using the condition keyec2:SourceOutpostArnfor designated Outposts, whereec2:OutpostArnis null (the destination is not the Outpost). -
The
ec2:CopySnapshot*actions should not be allowed to principals that don't need it. Transfer of snapshots from an Outpost to a Region is not currently supported. However, snapshots can be copied from Region to an Outposts (for example, a valid use case is to move an Amazon Machine Image (AMI) from Region to an Outpost for faster launching or removing repeated bandwidth consumption). You can use the ec2:OutpostArn condition key if you need to restrict the copying of snapshots to a specified Outpost. If you need to restrict copying snapshots to specific Regions, then specify the Region portion of the ARN within the resource attribute of the policy statement. -
For each of the following actions, only grant them if there is a known requirement for the principal, and use the policy's resource section to only allow the storage in the required Region:
-
rds:CreateDBSnapshot -
rds:CreateDBClusterSnapshot -
elasticache:CreateSnapshot -
elasticache:CopySnapshot -
ec2:CopyImage -
ec2:CreateInstanceExportTask -
ec2:CreateVolume -
ec2:AttachVolume -
ec2:ImportSnapshot -
ec2:ImportVolume -
datasync:Create* -
datasync:Update*
-
-
Implement permission guardrails for which include each of the applicable restrictions defined in this best practice
Resources
Related best practices:
Related documentation: