|
@@ -1,197 +0,0 @@
|
|
|
-{
|
|
|
- "Version": "2012-10-17",
|
|
|
- "Statement": [
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "sqs:ListQueues",
|
|
|
- "sqs:GetQueueUrl",
|
|
|
- "sqs:ListDeadLetterSourceQueues",
|
|
|
- "sqs:ReceiveMessage",
|
|
|
- "sqs:GetQueueAttributes",
|
|
|
- "sqs:ListQueueTags",
|
|
|
- "sqs:CreateQueue",
|
|
|
- "sqs:SendMessage",
|
|
|
- "sqs:SetQueueAttributes",
|
|
|
- "sqs:TagQueue"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "cloudtrail:StopLogging",
|
|
|
- "cloudtrail:StartLogging",
|
|
|
- "cloudtrail:AddTags",
|
|
|
- "cloudtrail:DeleteTrail",
|
|
|
- "cloudtrail:UpdateTrail",
|
|
|
- "cloudtrail:CreateTrail",
|
|
|
- "cloudtrail:ListTags",
|
|
|
- "cloudtrail:GetTrailStatus",
|
|
|
- "cloudtrail:RemoveTags"
|
|
|
- ],
|
|
|
- "Resource": "arn:aws:cloudtrail:us-east-1:477548533976:trail/aws-cis-trail*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "cloudtrail:LookupEvents",
|
|
|
- "cloudtrail:PutEventSelectors",
|
|
|
- "cloudtrail:ListPublicKeys",
|
|
|
- "cloudtrail:ListTags",
|
|
|
- "cloudtrail:GetEventSelectors",
|
|
|
- "cloudtrail:DescribeTrails"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "events:DescribeRule",
|
|
|
- "events:ListRuleNamesByTarget",
|
|
|
- "events:EnableRule",
|
|
|
- "events:ListRules",
|
|
|
- "events:ListTargetsByRule"
|
|
|
- ],
|
|
|
- "Resource": "arn:aws:events:us-east-1:477548533976:rule/aws-cis-cloudtrail-status-check"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "events:PutTargets",
|
|
|
- "events:PutRule",
|
|
|
- "events:TestEventPattern"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "events:DescribeRule",
|
|
|
- "events:ListRuleNamesByTarget",
|
|
|
- "events:EnableRule",
|
|
|
- "events:ListRules",
|
|
|
- "events:ListTargetsByRule"
|
|
|
- ],
|
|
|
- "Resource": [
|
|
|
- "arn:aws:events:us-east-1:477548533976:rule/aws-cis-password-policy-check",
|
|
|
- "arn:aws:events:us-east-1:477548533976:rule/aws-cis-root-account-check",
|
|
|
- "arn:aws:events:us-east-1:477548533976:rule/aws-cis-user-policies-check",
|
|
|
- "arn:aws:events:us-east-1:477548533976:rule/aws-cis-support-group-check"
|
|
|
- ]
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "lambda:GetFunction",
|
|
|
- "lambda:ListVersionsByFunction",
|
|
|
- "lambda:GetPolicy"
|
|
|
- ],
|
|
|
- "Resource": [
|
|
|
- "arn:aws:lambda:us-east-1:477548533976:function:aws-cis-password-policy-check",
|
|
|
- "arn:aws:lambda:us-east-1:477548533976:function:aws-cis-root-account-check",
|
|
|
- "arn:aws:lambda:us-east-1:477548533976:function:aws-cis-user-policies-check",
|
|
|
- "arn:aws:lambda:us-east-1:477548533976:function:aws-cis-support-group-check",
|
|
|
- "arn:aws:lambda:us-east-1:477548533976:function:aws-cis-cloudtrail-status-check"
|
|
|
- ]
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "events:PutEvents",
|
|
|
- "events:PutRule",
|
|
|
- "events:TestEventPattern"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": "kms:*",
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": "kms:*",
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "logs:ListTagsLogGroup",
|
|
|
- "logs:DisassociateKmsKey",
|
|
|
- "logs:DeleteSubscriptionFilter",
|
|
|
- "logs:DescribeLogGroups",
|
|
|
- "logs:UntagLogGroup",
|
|
|
- "logs:DeleteLogGroup",
|
|
|
- "logs:DescribeLogStreams",
|
|
|
- "logs:DescribeSubscriptionFilters",
|
|
|
- "logs:DescribeMetricFilters",
|
|
|
- "logs:DeleteLogStream",
|
|
|
- "logs:PutLogEvents",
|
|
|
- "logs:CreateExportTask",
|
|
|
- "logs:PutMetricFilter",
|
|
|
- "logs:CreateLogStream",
|
|
|
- "logs:DeleteMetricFilter",
|
|
|
- "logs:TagLogGroup",
|
|
|
- "logs:DeleteRetentionPolicy",
|
|
|
- "logs:GetLogEvents",
|
|
|
- "logs:AssociateKmsKey",
|
|
|
- "logs:FilterLogEvents",
|
|
|
- "logs:PutSubscriptionFilter",
|
|
|
- "logs:PutRetentionPolicy"
|
|
|
- ],
|
|
|
- "Resource": [
|
|
|
- "arn:aws:logs:us-east-1:477548533976:log-group:aws-cis-logs*",
|
|
|
- "arn:aws:logs:us-east-1:477548533976:log-group::log-stream:"
|
|
|
- ]
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "logs:DeleteResourcePolicy",
|
|
|
- "logs:DescribeExportTasks",
|
|
|
- "logs:PutResourcePolicy",
|
|
|
- "logs:PutDestinationPolicy",
|
|
|
- "logs:CancelExportTask",
|
|
|
- "logs:TestMetricFilter",
|
|
|
- "logs:DeleteDestination",
|
|
|
- "logs:CreateLogGroup",
|
|
|
- "logs:DescribeResourcePolicies",
|
|
|
- "logs:PutDestination",
|
|
|
- "logs:DescribeDestinations"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": [
|
|
|
- "sns:CreatePlatformApplication",
|
|
|
- "sns:SetSMSAttributes",
|
|
|
- "sns:ListTopics",
|
|
|
- "sns:GetPlatformApplicationAttributes",
|
|
|
- "sns:CreatePlatformEndpoint",
|
|
|
- "sns:Unsubscribe",
|
|
|
- "sns:GetSubscriptionAttributes",
|
|
|
- "sns:ListSubscriptions",
|
|
|
- "sns:CheckIfPhoneNumberIsOptedOut",
|
|
|
- "sns:OptInPhoneNumber",
|
|
|
- "sns:DeleteEndpoint",
|
|
|
- "sns:SetEndpointAttributes",
|
|
|
- "sns:ListPhoneNumbersOptedOut",
|
|
|
- "sns:ListEndpointsByPlatformApplication",
|
|
|
- "sns:GetEndpointAttributes",
|
|
|
- "sns:SetSubscriptionAttributes",
|
|
|
- "sns:DeletePlatformApplication",
|
|
|
- "sns:SetPlatformApplicationAttributes",
|
|
|
- "sns:ListPlatformApplications",
|
|
|
- "sns:GetSMSAttributes"
|
|
|
- ],
|
|
|
- "Resource": "*"
|
|
|
- },
|
|
|
- {
|
|
|
- "Effect": "Allow",
|
|
|
- "Action": "sns:*",
|
|
|
- "Resource": "arn:aws:sns:us-east-1:477548533976:dps-alarm"
|
|
|
- }
|
|
|
- ]
|
|
|
-}
|