@@ -89,13 +89,6 @@ Resources:
89
89
Value : !Ref pSRASolutionName
90
90
91
91
rGuardDutyDeliveryS3BucketPolicy :
92
- # temp retain for troubleshooting
93
- DeletionPolicy : Retain
94
- # Metadata:
95
- # cfn_nag:
96
- # rules_to_suppress:
97
- # - id: F16
98
- # reason: "Opt-in regions may be used and so conditional policy is required"
99
92
Type : AWS::S3::BucketPolicy
100
93
Properties :
101
94
Bucket : !Ref rGuardDutyDeliveryS3Bucket
@@ -134,19 +127,18 @@ Resources:
134
127
Principal :
135
128
Service :
136
129
- guardduty.amazonaws.com
137
-
138
- # Bucket perm/location check allow for potential opt-in regions
139
- - Sid : AWSBucketPermissionsCheckOptinRegions
140
- Effect : Allow
141
- Action :
142
- - s3:GetBucketAcl
143
- - s3:GetBucketLocation
144
- - s3:ListBucket
145
- Resource : !Sub arn:aws:s3:::${rGuardDutyDeliveryS3Bucket}
146
- Principal :
147
- Service :
148
- - guardduty.ap-southeast-4.amazonaws.com
130
+ - guardduty.af-south-1.amazonaws.com
149
131
- guardduty.ap-east-1.amazonaws.com
132
+ - guardduty.ap-south-2.amazonaws.com
133
+ - guardduty.ap-southeast-3.amazonaws.com
134
+ - guardduty.ap-southeast-4.amazonaws.com
135
+ - guardduty.ca-west-1.amazonaws.com
136
+ - guardduty.eu-south-1.amazonaws.com
137
+ - guardduty.eu-south-2.amazonaws.com
138
+ - guardduty.eu-central-2.amazonaws.com
139
+ - guardduty.me-south-1.amazonaws.com
140
+ - guardduty.me-central-1.amazonaws.com
141
+ - guardduty.il-central-1.amazonaws.com
150
142
151
143
- Sid : AWSBucketDelivery
152
144
Effect : Allow
@@ -158,19 +150,18 @@ Resources:
158
150
Principal :
159
151
Service :
160
152
- guardduty.amazonaws.com
161
-
162
- # Bucket delivery allow for potential opt-in regions
163
- - Sid : AWSBucketDeliveryOptinRegions
164
- Effect : Allow
165
- Action : s3:PutObject
166
- # Condition:
167
- # StringEquals:
168
- # s3:x-amz-acl: bucket-owner-full-control
169
- Resource : !Sub arn:aws:s3:::${rGuardDutyDeliveryS3Bucket}/*
170
- Principal :
171
- Service :
172
- - guardduty.ap-southeast-4.amazonaws.com
153
+ - guardduty.af-south-1.amazonaws.com
173
154
- guardduty.ap-east-1.amazonaws.com
155
+ - guardduty.ap-south-2.amazonaws.com
156
+ - guardduty.ap-southeast-3.amazonaws.com
157
+ - guardduty.ap-southeast-4.amazonaws.com
158
+ - guardduty.ca-west-1.amazonaws.com
159
+ - guardduty.eu-south-1.amazonaws.com
160
+ - guardduty.eu-south-2.amazonaws.com
161
+ - guardduty.eu-central-2.amazonaws.com
162
+ - guardduty.me-south-1.amazonaws.com
163
+ - guardduty.me-central-1.amazonaws.com
164
+ - guardduty.il-central-1.amazonaws.com
174
165
175
166
- Sid : DenyUnencryptedObjectUploads
176
167
Effect : Deny
@@ -182,19 +173,18 @@ Resources:
182
173
Principal :
183
174
Service :
184
175
- guardduty.amazonaws.com
185
-
186
- # Unencryption object upload deny for potential opt-in regions
187
- - Sid : DenyUnencryptedObjectUploadsOptinRegions
188
- Effect : Deny
189
- Action : s3:PutObject
190
- Condition :
191
- StringNotEquals :
192
- s3:x-amz-server-side-encryption : aws:kms
193
- Resource : !Sub arn:aws:s3:::${rGuardDutyDeliveryS3Bucket}/*
194
- Principal :
195
- Service :
196
- - guardduty.ap-southeast-4.amazonaws.com
176
+ - guardduty.af-south-1.amazonaws.com
197
177
- guardduty.ap-east-1.amazonaws.com
178
+ - guardduty.ap-south-2.amazonaws.com
179
+ - guardduty.ap-southeast-3.amazonaws.com
180
+ - guardduty.ap-southeast-4.amazonaws.com
181
+ - guardduty.ca-west-1.amazonaws.com
182
+ - guardduty.eu-south-1.amazonaws.com
183
+ - guardduty.eu-south-2.amazonaws.com
184
+ - guardduty.eu-central-2.amazonaws.com
185
+ - guardduty.me-south-1.amazonaws.com
186
+ - guardduty.me-central-1.amazonaws.com
187
+ - guardduty.il-central-1.amazonaws.com
198
188
199
189
- Sid : DenyIncorrectEncryptionHeader
200
190
Effect : Deny
@@ -206,19 +196,18 @@ Resources:
206
196
Principal :
207
197
Service :
208
198
- guardduty.amazonaws.com
209
-
210
- # Incorrect encryption header deny for potential opt-in regions
211
- - Sid : DenyIncorrectEncryptionHeaderOptinRegions
212
- Effect : Deny
213
- Action : s3:PutObject
214
- Condition :
215
- StringNotEquals :
216
- s3:x-amz-server-side-encryption-aws-kms-key-id : !Sub ${pGuardDutyOrgDeliveryKMSKeyArn}
217
- Resource : !Sub arn:aws:s3:::${rGuardDutyDeliveryS3Bucket}/*
218
- Principal :
219
- Service :
220
- - guardduty.ap-southeast-4.amazonaws.com
199
+ - guardduty.af-south-1.amazonaws.com
221
200
- guardduty.ap-east-1.amazonaws.com
201
+ - guardduty.ap-south-2.amazonaws.com
202
+ - guardduty.ap-southeast-3.amazonaws.com
203
+ - guardduty.ap-southeast-4.amazonaws.com
204
+ - guardduty.ca-west-1.amazonaws.com
205
+ - guardduty.eu-south-1.amazonaws.com
206
+ - guardduty.eu-south-2.amazonaws.com
207
+ - guardduty.eu-central-2.amazonaws.com
208
+ - guardduty.me-south-1.amazonaws.com
209
+ - guardduty.me-central-1.amazonaws.com
210
+ - guardduty.il-central-1.amazonaws.com
222
211
223
212
224
213
Outputs :
0 commit comments