Ensure that your Object Storage Service (OSS) buckets are configured to allow access only to selected, trusted networks (i.e. authorized IP addresses/IP address ranges) in order to protect against unapproved access. Before running this Trend Vision One™ - Cloud Posture rule, you must define the list of public IPv4 addresses and/or IPv4 address ranges that are permitted to access your OSS buckets in the rule settings on your Trend Vision One™ account.
Allowing public and unauthorized access to your Object Storage Service (OSS) buckets can lead to unapproved actions such as viewing, uploading, modifying, or deleting OSS objects. To prevent Object Storage Service (OSS) data exposure, data loss, unexpected charges on your Alibaba Cloud bill or you just want a central place to manage bucket access using bucket policies, make sure that your OSS buckets are accessible to selected networks only.
Audit
To determine if the access to your OSS buckets is limited to selected networks via bucket policies, perform the following operations:
Remediation / Resolution
To ensure that OSS bucket access is limited to selected, trusted networks only via bucket policies, perform the following operations:
References
- Alibaba Cloud Documentation
- Buckets Overview
- Access And Control Overview
- Authorize other users to access OSS by using bucket policies
- ossutil Documentation
- bucket-policy