A Resource-Based Policy is an IAM policy attached to a resource rather than to an identity. It specifies which principals can access the resource and what actions they can perform. Unlike identity-based policies, resource-based policies can grant cross-account access without requiring the caller to assume a role.
A JSON document that defines permissions - which actions are allowed or denied on which AWS resources, and under what conditions.
A resource-based JSON policy attached to an S3 bucket that controls who can access the bucket and its objects, including cross-account and public access.
The ability to grant permissions for identities in one AWS account to access resources in another, typically using IAM roles with trust policies.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.