Skip to content

Amazon Bedrock access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Amazon Bedrock, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Amazon Bedrock connector needs.

Checks (4)

severity: critical Bedrock Agent Overprivileged Execution Role fix difficulty: medium #

Apply least-privilege policies to the agent execution role

  1. Open AWS IAM Console > Roles
  2. Find the agent's execution role
  3. Replace wildcard actions/resources with specific permissions

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: high Bedrock Agent Cross-Account Role fix difficulty: medium #

Remove cross-account resource references from the execution role

  1. Open AWS IAM Console > Roles
  2. Review policy statements for external account ARNs
  3. Replace with same-account resources or remove

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: high Bedrock Agent No Guardrail fix difficulty: medium #

Attach a Bedrock Guardrail to this agent

  1. Open AWS Bedrock Console > Guardrails
  2. Create or select an appropriate guardrail
  3. Attach it to the agent configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: medium Bedrock Agent Excessive Action Groups fix difficulty: medium #

Reduce the number of action groups to 3 or fewer

  1. Open AWS Bedrock Console > Agents
  2. Review action groups and consolidate or remove unnecessary ones

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

More Amazon Bedrock checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial