Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever an OSS bucket authority change is made. Your alert monitoring rule should query ActionTrail logs for events related to OSS bucket configurations, such as "PutBucketPolicy", "PutBucketEncryption", and "DeleteBucketPolicy".
Using Simple Log Service (SLS) alerts to detect OSS bucket authority changes helps prevent accidental or intentional modifications that could lead to unauthorized access or other security breaches. For example, actively monitoring OSS bucket policies can help organizations quickly identify and address overly permissive policies on critical data buckets.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor OSS bucket authority changes, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for OSS bucket authority changes, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.