Skip to content

Commit cfd19e7

Browse files
committed
Adding data perimeter service-specific guidance
1 parent a0f8b00 commit cfd19e7

25 files changed

+37
-7
lines changed

service_control_policies/service_specific_controls/restrict_nonvpc_deployment_scp.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -163,4 +163,4 @@
163163
}
164164
}
165165
]
166-
}
166+
}

service_specific_guidance/accessanalyzer-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: AWS Identity and Access Management Access Analyzer
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for AWS Identity and Access Management Access Analyzer. IAM Access Analyzer helps you to set, verify, and refine your IAM policies by providing a suite of capabilities. Its features include findings for external and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies.
5+
This document outlines service-specific guidance for implementing a data perimeter for AWS Identity and Access Management Access Analyzer.
6+
7+
IAM Access Analyzer helps you to set, verify, and refine your IAM policies by providing a suite of capabilities. Its features include findings for external and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/acm-pca-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: AWS Private Certificate Authority
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for AWS Private Certificate Authority (AWS Private CA). AWS Private CA is a managed service that allows you to create and manage private certificate authorities (CAs) within your organization. It enables you to issue and manage private certificates for your internal applications, services, and devices, providing secure communication and authentication within your AWS environment and on-premises infrastructure.
5+
This document outlines service-specific guidance for implementing a data perimeter for AWS Private Certificate Authority (AWS Private CA).
6+
7+
AWS Private CA is a managed service that allows you to create and manage private certificate authorities (CAs) within your organization. It enables you to issue and manage private certificates for your internal applications, services, and devices, providing secure communication and authentication within your AWS environment and on-premises infrastructure.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/acm-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: AWS Certificate Manager
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for AWS Certificate Manager (ACM). ACM is a service that simplifies the process of provisioning, managing, and deploying public and private SSL/TLS certificates for use with AWS services and your internal connected resources. ACM handles the complexity of creating, storing, and renewing SSL/TLS certificates, helping you secure your applications and websites while reducing the time-consuming manual process of managing certificates.
5+
This document outlines service-specific guidance for implementing a data perimeter for AWS Certificate Manager (ACM).
6+
7+
ACM is a service that simplifies the process of provisioning, managing, and deploying public and private SSL/TLS certificates for use with AWS services and your internal connected resources. ACM handles the complexity of creating, storing, and renewing SSL/TLS certificates, helping you secure your applications and websites while reducing the time-consuming manual process of managing certificates.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/amp-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: Amazon Managed Service for Prometheus
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for Amazon Managed Service for Prometheus. Amazon Managed Service for Prometheus is a fully managed monitoring service that makes it easy to monitor containerized applications and infrastructure at scale. It provides a highly available, secure, and managed environment for Prometheus, an open-source monitoring and alerting tool, allowing users to collect, store, and analyze metrics from their applications and infrastructure without the need to manage the underlying infrastructure.
5+
This document outlines service-specific guidance for implementing a data perimeter for Amazon Managed Service for Prometheus.
6+
7+
Amazon Managed Service for Prometheus is a fully managed monitoring service that makes it easy to monitor containerized applications and infrastructure at scale. It provides a highly available, secure, and managed environment for Prometheus, an open-source monitoring and alerting tool, allowing users to collect, store, and analyze metrics from their applications and infrastructure without the need to manage the underlying infrastructure.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/apigateway-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: Amazon API Gateway Management
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for Amazon API Gateway. Amazon API Gateway is a fully managed service that enables developers to create, publish, maintain, monitor, and secure APIs at any scale. It acts as a "front door" for applications to access data, business logic, or functionality from your backend services, such as workloads running on Amazon EC2, code running on AWS Lambda, or any web application. API Gateway handles all the tasks involved in accepting and processing up to hundreds of thousands of concurrent API calls, including traffic management, authorization and access control, monitoring, and API version management.
5+
This document outlines service-specific guidance for implementing a data perimeter for Amazon API Gateway.
6+
7+
Amazon API Gateway is a fully managed service that enables developers to create, publish, maintain, monitor, and secure APIs at any scale. It acts as a "front door" for applications to access data, business logic, or functionality from your backend services, such as workloads running on Amazon EC2, code running on AWS Lambda, or any web application. API Gateway handles all the tasks involved in accepting and processing up to hundreds of thousands of concurrent API calls, including traffic management, authorization and access control, monitoring, and API version management.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/apprunner-specific-guidance.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
# Service-specific guidance: AWS App Runner
33

44

5-
This document outlines service-specific guidance for implementing a data perimeter for AWS App Runner. AWS App Runner is a fully managed service that makes it easy to deploy containerized web applications and APIs at scale. It automatically builds and deploys your code, handles load balancing, scaling, and provides a secure HTTPS endpoint, allowing developers to focus on their application code rather than infrastructure management.
5+
This document outlines service-specific guidance for implementing a data perimeter for AWS App Runner.
6+
7+
AWS App Runner is a fully managed service that makes it easy to deploy containerized web applications and APIs at scale. It automatically builds and deploys your code, handles load balancing, scaling, and provides a secure HTTPS endpoint, allowing developers to focus on their application code rather than infrastructure management.
68

79

810
The following table specifies whether additional considerations apply to a specific data perimeter control objective, followed by the list of considerations and recommended controls, if any.

service_specific_guidance/appsync-specific-guidance.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33

44

55
This document outlines service-specific guidance for implementing a data perimeter for AWS AppSync.
6+
67
AWS AppSync is a fully managed service that enables developers to create scalable GraphQL APIs. It simplifies the process of building applications by allowing you to easily connect to various data sources, including AWS DynamoDB, Lambda, and HTTP APIs. AppSync handles real-time data synchronization and offline programming models, making it ideal for building responsive and collaborative applications across web and mobile platforms.
78

89

service_specific_guidance/artifact-specific-guidance.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33

44

55
This document outlines service-specific guidance for implementing a data perimeter for AWS Artifact.
6+
67
AWS Artifact is a self-service portal that provides on-demand access to AWS' compliance reports and agreements. It allows customers to download AWS security and compliance documents, such as ISO certifications, PCI reports, and SOC reports, to support their regulatory and compliance requirements. AWS Artifact helps organizations demonstrate AWS infrastructure compliance to auditors and regulators.
78

89

service_specific_guidance/codeartifact-specific-guidance.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33

44

55
This document outlines service-specific guidance for implementing a data perimeter for AWS CodeArtifact.
6+
67
AWS CodeArtifact is a fully managed artifact repository service that makes it easy for organizations to securely store, publish, and share software packages used in their software development process. It integrates with commonly used build tools and package managers, allowing developers to easily retrieve dependencies while maintaining control over package access and versioning.
78

89

0 commit comments

Comments
 (0)