Amazon_SQS_2

Ensure SQS Cross Account Access is not enabled

Description

Allowing untrusted cross-account access to your AWS SQS queues can produce to unauthorized actions such as intercepting, deleting or sending queue messages without permission. To prevent data leaks, data loss and unexpected charges on your AWS bill you need to grant access only to trusted entities by implementing the appropriate SQS policies.

Remediation

Perform the following steps to disable cross-account access of SQS Queue :

  1. Sign in to the AWS Management Console.
  2. click to SQS dashboard at https://console.aws.amazon.com/sqs/.
  3. Select the SQS queue that you want to update.
  4. Select the Permissions tab from the bottom panel.
  5. Identify each insecure policy statement to edit the selected policy statement. You can also open and edit directly the entire policy document by using the Edit Policy Document (Advanced) button.
  6. Inside the Add a Permission to &lt

Service

SQS

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!