AWS guidance highlights Resource Control Policies (RCPs) as organization-level guardrails that constrain resource policies, including access granted to principals outside an AWS Organization. RCPs complement Service Control Policies by applying to external principals, helping prevent attacker-controlled accounts from bypassing internal SCP restrictions. They can enforce data-perimeter standards for cross-account access, IAM role assumption, OIDC federation, and transport security, alongside controls such as VPC Block Public Access and centrally managed root access.
For Amazon S3, AWS supports bucket and access-point policies using s3:TlsVersion and aws:SecureTransport to require stronger encryption in transit, including TLS 1.3 where needed; AWS service API endpoints require TLS 1.2 or later by default. Organizations should use IAM Access Analyzer and access logs to identify dependencies, test RCPs in sandbox accounts, and roll them out progressively because RCPs lack an audit-only mode and can generate generic AccessDenied errors. Legacy TLS clients can be isolated behind CloudFront, while S3 Access Points allow stricter TLS requirements for selected access paths to the same data.

Map this exposure pattern across your cloud, code, and identities.
11 events from the most recent confirmed update back to the earliest known activity.
AWS published a blog post announcing that all AWS service API endpoints would be updated to require at least TLS 1.2.
Amazon S3 introduced the s3:TlsVersion IAM policy condition key, enabling customers to enforce TLS protocol-version requirements for S3 requests.
Amazon S3 launched in 2006 with support for object access over either HTTP or HTTPS.
AWS announced private resource-sharing options across VPC and AWS-account boundaries using AWS PrivateLink, VPC Lattice, Amazon EventBridge, and AWS Step Functions.
AWS announced CloudFront VPC origins, allowing private-subnet EC2 instances, ALBs, and NLBs to be fronted by CloudFront, and announced ALB header modification for changes including HSTS header insertion.
AWS announced an Incident Response service as part of its security-relevant product announcements.
AWS released centrally managed root access for AWS accounts, enabling tightly controlled root-level recovery actions such as correcting a misconfigured S3 bucket policy.
AWS introduced organization-level Declarative Policies for six EC2-related settings, including IMDSv2 enforcement and AMI-use restrictions, along with VPC Block Public Access to prevent unintended public EC2 exposure.
AWS updated its data-perimeter-policy-examples repository with RCP examples, including policies to restrict IAM role assumption to organization identities or approved third parties and constrain trusted OIDC tenants.
AWS released Resource Control Policies (RCPs), organization-level guardrails that constrain resource policies and can restrict public or unauthorized external access to resources such as S3 buckets.
AWS required a minimum of TLS 1.2 for all service API endpoints, including Amazon S3. AWS said S3 bucket and Access Point policies requiring TLS 1.2 were therefore no longer necessary, though policies can still enforce TLS 1.3 or higher.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
7 references tracked. Mallory keeps watching after this page renders.
docs.aws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourcewiz.io
Open sourcewiz.io
Open sourceaws.amazon.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.