OCI-ObjectStore-Object-Store-Policy-Protection

Severity : Medium

Description: This control ensures that OCI Object Storage buckets are protected against unintended and malicious deletion by unauthorized groups and users . Regular users/groups for the buckets and its objects must be configured with least privilege to only specific objects or buckets. Also access policies for non-privilege users and groups should remove add statements for permission for OBJECT-DELETE or BUCKET_DELETE with statement request.permission != {OBJECT_DELETE, BUCKET_DELETE}.

Remediation Steps:

Perform following to update bucket access policies :

  1. Login to the OCI console at Cloud Sign In .

  2. In the navigation, Click Identity & Security.

  3. Under Identity, click Policies.

  4. Select the compartment and then reported policy .  The policy's details and statements are displayed.

  5. Click Edit Policy Statements.

  6. In Policy Builder Select Basic or Advance editor to update the policy statements with request.permission != {OBJECT_DELETE, BUCKET_DELETE}.

  7. Click Save Changes.

Important:

Reference:

Blue Hexagon Proprietary