用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-database-4-1命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-database-4.1 |
| description | Ensure AWS Identity and Access Management (IAM) is in use |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","dynamodb","iam","access-control"] |
| cis_id | 4.1 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-4.2"] |
| prerequisites | [] |
| severity_boost | {} |
AWS Identity and Access Management (IAM) lets you securely control your users' access to AWS services and resources. To manage access control for Amazon DynamoDB, you can create IAM policies that control access to tables and data.
IAM policies help you control and maintain access to Amazon DynamoDB as needed.
N/A
Open IAM Console
Navigate to Policies
Policies.Create Policy
Create policy.Create policy page.Choose Service
Choose a service.DynamoDB in the search box and select it.Configure Actions
Actions section, select the actions you want to allow the user to perform.Read to allow read actions like GetItem, Scan, Query, etc.Set Resources
Resources section, you can specify which tables this policy applies to.Review Policy
Review policy.Create policy.Attach Policy
Users, Groups, or Roles section in the IAM console.Add permissions.Attach existing policies directly.Attach policy.IAM policies are in place that control access to DynamoDB tables and data, following the principle of least privilege.
Follow the same steps as the audit procedure to create and attach IAM policies for DynamoDB access control.
By default, no IAM policies are created for DynamoDB access. Users with AWS account root credentials have full access.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.3 Configure Data Access Control Lists | x | x | x |
| v7 | 14.6 Protect Information through Access Control Lists | x | x | x |
Level 1 | Manual