Skip to content

Commit 8ce934b

Browse files
[IT-4757] Reduce scope of Security Auditor role
The Security Auditor role is currently unused. Reduce access to a level appropriate for a security contractor being onboarded. Access is only needed in the security-central account, no access to Billing, Macie, or Elastic Beanstalk is needed.
1 parent 6ef0206 commit 8ce934b

File tree

1 file changed

+1
-4
lines changed

1 file changed

+1
-4
lines changed

org-formation/700-aws-sso/_tasks.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -495,7 +495,7 @@ SsoSecurityAuditor:
495495
IncludeMasterAccount: true
496496
OrganizationBindings:
497497
TargetBinding:
498-
Account: '*'
498+
Account: !Ref SecurityCentralAccount
499499
Parameters:
500500
instanceArn: !Ref instanceArn
501501
principalId: !Ref securityAuditorGroup
@@ -505,9 +505,6 @@ SsoSecurityAuditor:
505505
- 'arn:aws:iam::aws:policy/job-function/SupportUser'
506506
- 'arn:aws:iam::aws:policy/AmazonInspector2ReadOnlyAccess'
507507
- 'arn:aws:iam::aws:policy/AWSSecurityHubReadOnlyAccess'
508-
- 'arn:aws:iam::aws:policy/AWSElasticBeanstalkReadOnly'
509-
- 'arn:aws:iam::aws:policy/AWSBillingReadOnlyAccess'
510-
- 'arn:aws:iam::aws:policy/AmazonMacieReadOnlyAccess'
511508
sessionDuration: 'PT1H'
512509
masterAccountId: !Ref MasterAccount
513510

0 commit comments

Comments
 (0)