Home icon

Establishing a data perimeter on AWS: Analyze your account activity to evaluate impact and refine controls

Security Blog



This article provides guidance on analyzing your AWS account activity to evaluate the impact of implementing data perimeter controls and refine those controls as needed. It covers the following key points:

Specifically, the article covers:

  • Setting up prerequisites like CloudTrail trails, Athena tables, AWS Config aggregators, and the open-source data perimeter helper tool
  • Reviewing API calls to untrusted S3 buckets and refining your resource perimeter policy
  • Reviewing granted access and API calls by untrusted identities on your S3 buckets and refining your identity perimeter policy
  • Investigating resource configurations like AWS Lambda functions to support implementing network perimeter controls
  • Investigating access denied errors to help troubleshoot your deployed controls

The article concludes by providing steps to clean up the configured resources if you were just testing the solution.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 14
2024
Monitoring AWS Storage Gateway health and performance using Amazon CloudWatch
May 29
2024
AWS analytics services streamline user access to data, permissions setting, and auditing
Aug 28
2026
Extend your data perimeter to the AWS Management Console with Private Access
May 31
2024
Implementing network traffic inspection on AWS Outposts rack

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.