Checks whether a policy that meets the specified conditions is attached to each Resource Access Management (RAM) role. If so, the evaluation result is Compliant.

Scenarios

This rule applies when you need to grant specific permissions to a RAM role. This prevents security risks that may occur due to excessive permissions.

Risk level

Default risk level: medium.

When you configure this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If a policy that meets the specified conditions is attached to each RAM role, the evaluation result is Compliant.
  • If a policy that meets the specified conditions is not attached to a RAM role, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see Incompliance remediation.

Rule details

ItemDescription
Rule nameram-role-has-specified-policy
Rule identifierram-role-has-specified-policy
TagRAM, Role, and Policy
Automatic remediationNot supported
Trigger typePeriodic execution
Evaluation frequencyInterval of 24 hours
Supported resource typeRAM roles
Input parameter
  • action
  • effect. Default value: Allow.
  • resource

Incompliance remediation

Attach a policy that meets the specified conditions to a RAM role. For more information, see Modify the document and description of a custom policy.