conference-paper

Automating Cloud Security with Policy as Code: A Case Study on AWS S3 Buckets

  • UA Campus Repository (The University of Arizona)
  • University of Arizona
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Abstract

As cloud adoption grows and threats evolve, enforcing consistent and scalable security policies is increasingly challenging. Policy as Code (PaC) ad dresses this by enabling the definition, management, and automation of security policies through code. This paper explores PaC’s role in automating cloud security, with a focus on AWS environments. It high lights how integrating PaC into DevSecOps pipelines reduces misconfigurations, enhances transparency, and supports real-time compliance. Using a case study of AWS S3 buckets—often mis configured in public and government sectors—this research demonstrates how tools like AWS Cloud Formation Guard, Open Policy Agent (OPA), and CI/CD pipelines can enforce policies for secure and compliant configurations. These include checks for public access, encryption, and role-based access. The paper proposes a practical framework for scalable, testable, and auditable cloud governance using Policy as Code.

Record transparency

Publication details

OpenAlex
W7128566775
Document type
conference-paper
Language
EN
Source
UA Campus Repository (The University of Arizona)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.