3.4. 最低限必要な Service Control Policy (SCP)
Service Control Policy (SCP) の管理は、お客様の責任です。これらのポリシーは AWS Organization で維持され、割り当てられる AWS アカウント内で利用可能なサービスを管理します。
| 必須/任意 | サービス | アクション | 効果 |
|---|---|---|---|
| 必須 | Amazon EC2 | すべて | 許可 |
| Amazon EC2 Auto Scaling | すべて | 許可 | |
| Amazon S3 | すべて | 許可 | |
| アイデンティティーおよびアクセス管理 | すべて | 許可 | |
| Elastic Load Balancing | すべて | 許可 | |
| Elastic Load Balancing V2 | すべて | 許可 | |
| Amazon CloudWatch | すべて | 許可 | |
| Amazon CloudWatch Events | すべて | 許可 | |
| Amazon CloudWatch Logs | すべて | 許可 | |
| AWS Support | すべて | 許可 | |
| AWS Key Management Service | すべて | 許可 | |
| AWS Security Token Service | すべて | 許可 | |
| AWS Resource Tagging | すべて | 許可 | |
| AWS Route53 DNS | すべて | 許可 | |
| AWS Service Quotas | ListServices GetRequestedServiceQuotaChange GetServiceQuota RequestServiceQuotaIncrease ListServiceQuotas | 許可 | |
| 任意 | AWS Billing | ViewAccount Viewbilling ViewUsage | 許可 |
| AWS Cost and Usage Report | すべて | 許可 | |
| AWS Cost Explorer Services | すべて | 許可 |
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"autoscaling:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"s3:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"iam:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"elasticloadbalancing:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"cloudwatch:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"events:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"logs:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"support:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"kms:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"sts:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"tag:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"route53:*"
],
"Resource": [
"*"
]
},
{
"Effect": "Allow",
"Action": [
"servicequotas:ListServices",
"servicequotas:GetRequestedServiceQuotaChange",
"servicequotas:GetServiceQuota",
"servicequotas:RequestServiceQuotaIncrease",
"servicequotas:ListServiceQuotas"
],
"Resource": [
"*"
]
}
]
}