Skip to content

Commit 1b47c07

Browse files
committed
bedrock API key denial for service specific controls
1 parent 64bd40b commit 1b47c07

File tree

3 files changed

+26
-0
lines changed

3 files changed

+26
-0
lines changed

README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,8 @@ The example policies are divided into different categories based on the type of
3030

3131
* **[Sensitive data protection](Sensitive-data-protection/README.md)**: Implement controls that protect your sensitive data, that should not be made publicly accessible or deleted intentionally or unintentionally.
3232

33+
* **[Service Specific Controls](Service-Specific-Controls/README.md)**: Controls for specific AWS services
34+
3335

3436

3537

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
{
2+
"Version": "2012-10-17",
3+
"Statement": [
4+
{
5+
"Sid":"DenyBedRockShortAndLongTermAPIKeys",
6+
"Effect": "Deny",
7+
"Action": [
8+
"iam:CreateServiceSpecificCredential",
9+
"bedrock:CallWithBearerToken"
10+
],
11+
"Resource": [
12+
"*"
13+
]
14+
}
15+
]
16+
}
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
## Service Specific Controls
2+
3+
These policies provide guidance on how to accomplish security objectives for specific AWS services.
4+
5+
6+
| Included Policy | Rational |
7+
|------|-------------|
8+
|[Deny users from creating short term or long term Amazon Bedrock API keys.](Deny-Bedrock-Api-Keys.json)| Used to help enforce that users within your AWS organization cannot create service specific credentials for an IAM user for use with Amazon Bedrock, and denies the usage of Bedrock API keys with the Amazon Bedrock Service.|

0 commit comments

Comments
 (0)