Resource policies create a second authorisation surface
In cloud platforms, permission can be granted from the identity's side or from the resource's side, and both have to be considered.
A bucket can allow access to an account the account's own policies never mentioned. Reviewing only identity permissions therefore gives an incomplete answer, and resource policies are where accidental public or cross-account access usually originates.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
- Unused cloud permissions are latent attack pathsStill wired
