Skip to content

Commit ece3aa2

Browse files
committed
Updating data perimeter service-specific guidance.
1 parent 2e530e7 commit ece3aa2

24 files changed

+826
-1599
lines changed

service_specific_guidance/accessanalyzer-specific-guidance.md

Lines changed: 22 additions & 54 deletions
Original file line numberDiff line numberDiff line change
@@ -24,72 +24,40 @@ The following table specifies whether additional considerations apply to a speci
2424

2525
**List of service APIs reviewed against data perimeter control objectives**
2626

27-
* CreateAnalyzer
28-
29-
* ListAnalyzers
30-
27+
* ApplyArchiveRule
28+
* CancelPolicyGeneration
29+
* CheckAccessNotGranted
30+
* CheckNoNewAccess
31+
* CheckNoPublicAccess
3132
* CreateAccessPreview
32-
33+
* CreateAnalyzer
3334
* CreateArchiveRule
34-
35-
* StartPolicyGeneration
36-
37-
* ListFindings
38-
39-
* ListFindingsV2
40-
41-
* StartResourceScan
42-
35+
* DeleteAnalyzer
36+
* DeleteArchiveRule
4337
* GenerateFindingRecommendation
44-
45-
* ApplyArchiveRule
46-
47-
* TagResource
48-
49-
* UpdateArchiveRule
50-
51-
* UpdateFindings
52-
53-
* ListAccessPreviewFindings
54-
55-
* ListAccessPreviews
56-
57-
* ListAnalyzedResources
58-
59-
* ListArchiveRules
60-
61-
* ListPolicyGenerations
62-
63-
* ListTagsForResource
64-
6538
* GetAccessPreview
66-
6739
* GetAnalyzedResource
68-
6940
* GetAnalyzer
70-
7141
* GetArchiveRule
72-
7342
* GetFinding
74-
7543
* GetFindingV2
76-
7744
* GetGeneratedPolicy
78-
45+
* ListAccessPreviewFindings
46+
* ListAccessPreviews
47+
* ListAnalyzedResources
48+
* ListAnalyzers
49+
* ListArchiveRules
50+
* ListFindings
51+
* ListFindingsV2
52+
* ListPolicyGenerations
53+
* ListTagsForResource
54+
* StartPolicyGeneration
55+
* StartResourceScan
56+
* TagResource
7957
* UntagResource
80-
81-
* CancelPolicyGeneration
82-
83-
* CheckNoNewAccess
84-
58+
* UpdateArchiveRule
59+
* UpdateFindings
8560
* ValidatePolicy
8661

87-
* CheckAccessNotGranted
88-
89-
* CheckNoPublicAccess
90-
91-
* DeleteArchiveRule
92-
93-
* DeleteAnalyzer
9462

9563

service_specific_guidance/acm-pca-specific-guidance.md

Lines changed: 13 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -38,46 +38,24 @@ If you want to restrict access to trusted resources, consider implementing these
3838

3939
**List of service APIs reviewed against data perimeter control objectives**
4040

41-
* CreateCertificateAuthorityAuditReport
42-
4341
* CreateCertificateAuthority
44-
42+
* CreateCertificateAuthorityAuditReport
4543
* CreatePermission
46-
47-
* PutPolicy
48-
49-
* TagCertificateAuthority
50-
51-
* UpdateCertificateAuthority
52-
53-
* ListCertificateAuthorities
54-
55-
* ListPermissions
56-
57-
* ListTags
58-
44+
* DeleteCertificateAuthority
45+
* DeletePermission
46+
* DeletePolicy
47+
* DescribeCertificateAuthority
48+
* DescribeCertificateAuthorityAuditReport
5949
* GetCertificate
60-
6150
* GetCertificateAuthorityCertificate
62-
6351
* GetCertificateAuthorityCsr
64-
6552
* GetPolicy
66-
67-
* DescribeCertificateAuthority
68-
69-
* DescribeCertificateAuthorityAuditReport
70-
53+
* IssueCertificate
54+
* ListCertificateAuthorities
55+
* ListPermissions
56+
* ListTags
57+
* PutPolicy
7158
* RestoreCertificateAuthority
72-
59+
* TagCertificateAuthority
7360
* UntagCertificateAuthority
74-
75-
* IssueCertificate
76-
77-
* DeletePermission
78-
79-
* DeletePolicy
80-
81-
* DeleteCertificateAuthority
82-
83-
61+
* UpdateCertificateAuthority

service_specific_guidance/acm-specific-guidance.md

Lines changed: 10 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -35,38 +35,19 @@ If you want to restrict access to your networks to trusted identities and truste
3535
* **Preventative control example 2**: Consider using your existing security appliances such as outbound proxies to inspect service API calls in your environment for the identities making the calls and resources being accessed, and restrict the calls accordingly. This type of solution might have implications for security, scalability, latency, and reliability that you should evaluate carefully.
3636

3737

38-
39-
40-
41-
4238
**List of service APIs reviewed against data perimeter control objectives**
4339

44-
* ImportCertificate
45-
46-
* RequestCertificate
47-
48-
* ExportCertificate
49-
50-
* PutAccountConfiguration
51-
5240
* AddTagsToCertificate
53-
54-
* UpdateCertificateOptions
55-
56-
* ListCertificates
57-
58-
* ListTagsForCertificate
59-
41+
* DeleteCertificate
42+
* DescribeCertificate
43+
* ExportCertificate
6044
* GetAccountConfiguration
61-
6245
* GetCertificate
63-
64-
* DescribeCertificate
65-
66-
* RenewCertificate
67-
46+
* ImportCertificate
47+
* ListCertificates
48+
* ListTagsForCertificate
49+
* PutAccountConfiguration
6850
* RemoveTagsFromCertificate
69-
70-
* DeleteCertificate
71-
72-
51+
* RenewCertificate
52+
* RequestCertificate
53+
* UpdateCertificateOptions

service_specific_guidance/amp-specific-guidance.md

Lines changed: 15 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -19,52 +19,28 @@ The following table specifies whether additional considerations apply to a speci
1919
| Network perimeter | My resources can be accessed only from expected networks | Resource | RCP | N |
2020

2121
*Y – Additional considerations apply. N – No additional considerations apply.
22-
2322

2423
**List of service APIs reviewed against data perimeter control objectives**
2524

26-
* ListWorkspaces
27-
28-
* ListScrapers
29-
30-
* CreateWorkspace
31-
32-
* CreateRuleGroupsNamespace
33-
34-
* PutRuleGroupsNamespace
35-
3625
* CreateLoggingConfiguration
37-
26+
* CreateRuleGroupsNamespace
3827
* CreateScraper
39-
40-
* TagResource
41-
42-
* UpdateLoggingConfiguration
43-
44-
* UpdateWorkspaceAlias
45-
46-
* ListRuleGroupsNamespaces
47-
48-
* ListTagsForResource
49-
50-
* GetDefaultScraperConfiguration
51-
28+
* CreateWorkspace
29+
* DeleteLoggingConfiguration
30+
* DeleteRuleGroupsNamespace
31+
* DeleteScraper
32+
* DeleteWorkspace
5233
* DescribeLoggingConfiguration
53-
5434
* DescribeRuleGroupsNamespace
55-
5635
* DescribeScraper
57-
5836
* DescribeWorkspace
59-
37+
* GetDefaultScraperConfiguration
38+
* ListRuleGroupsNamespaces
39+
* ListScrapers
40+
* ListTagsForResource
41+
* ListWorkspaces
42+
* PutRuleGroupsNamespace
43+
* TagResource
6044
* UntagResource
61-
62-
* DeleteLoggingConfiguration
63-
64-
* DeleteRuleGroupsNamespace
65-
66-
* DeleteScraper
67-
68-
* DeleteWorkspace
69-
70-
45+
* UpdateLoggingConfiguration
46+
* UpdateWorkspaceAlias

0 commit comments

Comments
 (0)