QuestionQ24

Security and Compliance

A company uses an AWS Cloud Development Kit (AWS CDK) application for its infrastructure. The AWS CDK application creates AWS Lambda functions and the IAM roles attached to those functions. The company also uses AWS Organizations. The company’s developers can assume the AWS CDK application deployment role.

The company’s security team discovered that the developers and the role used to deploy the AWS CDK application have more permissions than required. The security team also found that the roles attached to the Lambda functions created by the CDK application have more permissions than necessary. The developers must not be able to grant additional permissions.

Which solution meets these requirements with the LEAST operational overhead?

Explanation

An IAM permissions boundary sets the maximum effective permissions for an IAM role or user. Applying it during AWS CDK bootstrapping constrains the CloudFormation execution role used for deployments, and configuring it as the CDK application’s default permissions boundary applies the same cap to IAM roles created by the application, including Lambda execution roles. This centrally prevents privilege escalation without depending on developers to specify a boundary for each role.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!