Control: 5.2 Ensure that there are no publicly accessible objects in storage buckets
Description
It is recommended that storage object ACL should not grant public access.
Remediation
From Console
- Logon to OSS console.
- In the bucket-list pane, click on a target OSS bucket.
- Click on
Files
in top middle of the console. - Hover on More in the right column on a target object.
- Click
Set ACL
. - Click
Private
. - Click
Save
.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_5_2
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_5_2 --share
SQL
This control uses a named query:
manual_control