ram-user-role-no-product-admin-access
Checks whether a Resource Access Management (RAM) role has administrator or cloud service administrator permissions. Roles without such permissions are evaluated as Compliant.
Scenarios
Enforces the principle of least privilege (PoLP) for RAM role permissions to prevent security risks from excessive access.
Risk level
Default risk level: medium.
You can change the risk level when you apply this rule.
Compliance evaluation logic
-
If the RAM role does not have administrator permissions or cloud service administrator permissions, the evaluation result is Compliant.
-
If the RAM role has administrator permissions and cloud service administrator permissions, the evaluation result is Non-compliant.
-
If the RAM role is a system role or a service-linked role, the evaluation result is Not Applicable.
Rule details
|
Item |
Description |
|
Rule name |
ram-user-role-no-product-admin-access |
|
Rule ID |
|
|
Tag |
RAM and Role |
|
Automatic remediation |
Not supported |
|
Trigger type |
Periodic execution |
|
Evaluation frequency |
Every 24 hours |
|
Supported resource type |
RAM role |
|
Input parameter |
None |
Non-compliance remediation
Remove administrator and cloud service administrator permissions from the RAM role. Modify the document and description of a custom policy.