Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever a RAM policy change is made. Your alert monitoring rule should query ActionTrail logs for events related to RAM policy operations, such as "CreatePolicy", "UpdatePolicyVersion", and "DeletePolicy".
Using Simple Log Service (SLS) alerts to detect RAM policy changes lets you proactively monitor and identify unauthorized modifications to access permissions. This helps maintain security by providing early warnings of potential security breaches and allowing for timely investigation and corrective actions.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor RAM policy changes in your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for RAM policy changes, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.