Overly Permissive Cloud Service Configuration
雲端服務權限配置過寬
Deployment
Risk Description
When an organization temporarily relaxes permissions to accelerate development and never revokes them; due to unmitigated control gaps, an audit finds the training data storage accessible from outside the organization, with no way to confirm whether it was previously downloaded, triggering compliance exposure and operational reputational costs.
Framework Mappings
NIST CSF 2.0PR.AA
ISO/IEC 27001Annex A 5.15、5.23、8.9
MITRE ATLASAML.T0024
NIST AI 600-1Data Privacy
ISO/IEC 5338部署
Risk Treatment & Implementation Guidance
Configure cloud resources under least privilege, with temporary relaxations auto-expiring; Audit cloud security configurations regularly, detecting externally open missettings; Log and alert on access to sensitive storage such as training data