S0095RS3-T14-S0095-Z · Full risk code

Overly Permissive Cloud Service Configuration

雲端服務權限配置過寬

Deployment
Risk Description

When an organization temporarily relaxes permissions to accelerate development and never revokes them; due to unmitigated control gaps, an audit finds the training data storage accessible from outside the organization, with no way to confirm whether it was previously downloaded, triggering compliance exposure and operational reputational costs.

Framework Mappings

NIST CSF 2.0PR.AA
ISO/IEC 27001Annex A 5.15、5.23、8.9
MITRE ATLASAML.T0024
NIST AI 600-1Data Privacy
ISO/IEC 5338部署

Risk Treatment & Implementation Guidance

Configure cloud resources under least privilege, with temporary relaxations auto-expiring; Audit cloud security configurations regularly, detecting externally open missettings; Log and alert on access to sensitive storage such as training data