- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`This rule evaluates whether Amazon Machine Images (AMIs) are shared with external AWS accounts or organizations that are not onboarded to Datadog. AMIs contain complete system images including operating systems, applications, and potentially sensitive data. Sharing AMIs with unauthorized external accounts or organizations can lead to data exposure and security risks.
The data contained in the launch_permissions
field is enumerated and the following types of principals are assessed:
user_id
- designates an AWS accountorganization_arn
- designates an organization from AWS Organizationsorganizational_unit_arn
- designates an organizational unit (OU) from AWS OrganizationsThe control fails if any AWS account, organization, or OU present in launch_permissions
is not onboarded to Datadog.
Note: If the AMI is shared with a trusted third-party AWS account or organization that you cannot onboard to Datadog, mute the finding and leave a comment documenting the justification.
To remove external account or organization sharing permissions from Amazon Machine Images, follow the steps outlined in the Sharing an AMI section of the Amazon EC2 User Guide. For guidance regarding onboarding AWS accounts to Datadog, follow the Datadog AWS integration documentation to onboard the account. Ensure that resource collection and Cloud Security are correctly configured.