Automating Cloud Security with Policy as Code: A Case Study on AWS S3 Buckets
At a glance
- Citations
- 0
- References
- 0
- Comments
- 0
Abstract
As cloud adoption grows and threats evolve, enforcing consistent and scalable security policies is increasingly challenging. Policy as Code (PaC) ad dresses this by enabling the definition, management, and automation of security policies through code. This paper explores PaC’s role in automating cloud security, with a focus on AWS environments. It high lights how integrating PaC into DevSecOps pipelines reduces misconfigurations, enhances transparency, and supports real-time compliance. Using a case study of AWS S3 buckets—often mis configured in public and government sectors—this research demonstrates how tools like AWS Cloud Formation Guard, Open Policy Agent (OPA), and CI/CD pipelines can enforce policies for secure and compliant configurations. These include checks for public access, encryption, and role-based access. The paper proposes a practical framework for scalable, testable, and auditable cloud governance using Policy as Code.
Publication details
- OpenAlex
- W7128566775
- Document type
- conference-paper
- Language
- EN
- Source
- UA Campus Repository (The University of Arizona)
- Last metadata update
Comments
Log in to join the discussion.