Blog
Updates in Data Access Security: AWS S3 Connector
Author
TanyaB
SailPoint
The new AWS S3 Bucket Connector extends Data Access Security’s (DAS) Data Discovery, Permissions Analysis, and Access Reviews capabilities to resources and files stored on AWS S3 Buckets. It helps organizations attain a comprehensive governance posture and gain greater visibility into access to all data across their AWS S3 environment.
What are the new capabilities?
The DAS AWS S3 Connector enables admins, business users, and data owners to view where data resides and how it is organized within S3 accounts and buckets throughout the organization. It helps you understand who has access to that data and analyze access rights for AWS IAM Identities across multiple Regions, Organizational Units, and External and Internal Accounts. You can also review granular access governance controls down to the file level and certify access to comply with regulations. Users can gain insights into Organization and Bucket-level Access Policies, Public Bucket Permissions and fine-grained ACL-based access rights for individual identities.
See the original DAS AWS S3 connector announcement for more details.
How do I configure the connection to AWS S3 in DAS?
Admins can configure it in DAS under Admin > Applications > Add New application.
For more information refer to the Adding an AWS S3 Application documentation.
You could run the Resource Discovery
Admins might want to run a resource discovery task from Settings > Task Management to gain visibility into AWS S3 folder access in a simplified hierarchical format, including AWS S3 buckets, and individual files, with region and OU labeling for easier cataloging and searches.
You could run the Permissions Analysis
Admins might want to run a resource discovery task from Settings > Task Management to gain granular visibility into identities, accounts, and entitlements access to AWS S3 buckets and files. This can even go down to the individual file level, including IAM & Bucket Level Policies, Public Bucket Permissions, ACL Based Access Control, External & Cross-Account Privileges, and Identities with direct or external access to AWS S3 data.
You could use other DAS features for AWS S3
With the connection of the AWS S3 application to the single pane of glass in DAS, admins, data owners, and compliance managers get additional set of capabilities for visibility and control over access to unstructured data. This includes automated and scheduled out-of-the-box reports detailing access to data stored on AWS S3, and insights into data access paths.
In addition, you could run data access certification campaigns to review and validate access to AWS S3 data assets down to the files level, or access rights granted through policies, public permissions and ACLs.
You could assign data owner to AWS S3 resources to delegate governance responsibilities to the people closest to the data.
What's Next on the Roadmap?
Admins will be able to gain more focus and control over access to unstructured data with:
- Detecting and cataloging sensitive data assets on AWS S3 environment.
- Monitoring and auditing data access activities on AWS S3 data assets, and alerting on unauthorized access through rule-based access policies.
Submit Questions or Feedback
Submit questions or feedback, and we'll be in touch.