Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever an OSS bucket permission change is made. Your alert monitoring rule should query Object Storage Service (OSS) logs for operations related to bucket permission changes such as "PutObjectAcl" operations.
By using Simple Log Service (SLS) alerts to detect OSS bucket permission changes, you can quickly pinpoint and address access issues for sensitive OSS buckets and their objects, minimizing security risks.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor OSS bucket permission changes in your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for detecting OSS bucket permission changes, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.