Securely share resources within an organization
As your business and the number of your applications grow, you may need to share resources across multiple applications. Sharing resources reduces costs and operational overhead. It also helps you centrally manage security policies and audit trails for shared resources. You must share resources securely within your organization to prevent accidental access and reduce the risk of data breaches.
Priority
Medium
What to avoid
Sharing resources directly between Alibaba Cloud accounts on a point-to-point basis leads to high operations management costs that scale with the number of resources and accounts. This method also relies on manual operations, which increases the risk of errors.
Allowing resource sharing outside the organization without control policies or other measures creates a threat of accidental external access.
Sharing and access outside the organization are not regularly reviewed.
Implementation guide
Use Resource Directory to organize and centrally manage your company's accounts. We recommend that you use the landing zone setup feature in Cloud Governance Center. This feature uses a blueprint template to help you easily build a multi-account architecture. A multi-account architecture lets you securely share resources within your organization.
Integrate Resource Directory with Alibaba Cloud services. Alibaba Cloud services that integrate with Resource Directory are called trusted services. Resource Directory allows trusted services to access information about members and folders in your resource directory. You can use a management account or a delegated administrator account for a trusted service to manage operations for your entire organization. This lets you share resource instances from the trusted service and simplifies the unified management of Alibaba Cloud services. For example, in a single-account scenario, you must purchase and configure Cloud Firewall for each Alibaba Cloud account. After you build a multi-account architecture with Resource Directory, you only need to purchase one Cloud Firewall instance in the management account. You can then centrally manage assets that are assigned public IP addresses for all accounts in your organization, configure defense policies, and view log analytics. This achieves centralized security management. For more information about trusted services that Resource Directory supports, see Overview of trusted services.
Use Resource Sharing to share resources within your organization. This unifies operations management and improves the sharing experience. For a list of Alibaba Cloud services that support Resource Sharing, see Alibaba Cloud services that support Resource Sharing. To ensure that resources are shared securely, we recommend that you share resources only within your resource directory. This prevents accidental sharing with accounts outside your organization and avoids security events such as data breaches.
Follow the best practice to set permission boundaries. Use control policies to centrally manage and restrict resource sharing. Permission boundaries ensure that specific resources or resource types are shared only with trusted Alibaba Cloud accounts within your organization. You can use control policies to prohibit resource sharing outside your organization or to allow sharing of only specific resource types. For examples, see Examples of using a control policy to restrict resource sharing.
Follow the best practice to periodically review public and cross-account access. Use access analytics to regularly review and detect access from outside your organization. Promptly address any external access caused by improper resource sharing to keep your company's assets and data secure.