--- name: cloud description: "Review cloud storage and service access through attributable ownership, least privilege, destination policy, and auditable configuration." --- # Cloud object storage Review cloud storage and service access through attributable ownership, least privilege, destination policy, and auditable configuration. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Cloud account and resource inventory - IAM and storage policies - Approved architecture and egress requirements ## Review guide ### 1. Establish ownership Tie each bucket, service identity, and integration to a documented account, environment, and responsible owner before drawing conclusions. ### 2. Review effective policy Evaluate identity, resource, network, and conditional policies together for the exact action and tenant context. ### 3. Constrain service egress Apply an explicit destination policy plus independent network controls for server-side requests. ### 4. Audit change paths Ensure configuration changes, public sharing, and credential rotation leave reviewable records and safe defaults. ## What to produce - Attributed asset inventory - Effective-permission review - Egress and audit controls ## Common mistakes - Calling an internet-visible asset owned without attribution - Reviewing IAM policies in isolation - Using a network control as the only destination check ## Reading and source context ### Resources - [AWS IAM security best practices for workload identities](https://vulns.co/research/resources/aws-iam-machine-identity-best-practices/) - [OWASP Server-Side Request Forgery Prevention](https://vulns.co/research/resources/owasp-server-request-destination-boundaries/) - [NIST SP 800-190: Application Container Security Guide](https://vulns.co/research/resources/nist-sp-800-190-container-isolation-guide/) ### Diagrams - [Layer server-request destination controls](https://vulns.co/research/diagrams/server-request-destination-policy/) - [Keep workload authority tenant-scoped](https://vulns.co/research/diagrams/workload-identity-tenant-scope/) ### Reports - [Shopify Exchange screenshot service crossed internal boundaries](https://vulns.co/research/reports/shopify-exchange-request-isolation-2019/) - [Meta service-identity exposure amplified by excessive secret access](https://vulns.co/research/reports/meta-service-identity-secrets-trust-boundary-2026/) - [Actifio driver execution exposed excessive shared-service authority](https://vulns.co/research/reports/google-actifio-driver-service-identity-isolation-2025/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/cloud/