Working with Access Policies
After creating the users and groups who can access the services in your accounts, the next step in the process is to craft the policies that provide only the access necessary for each user, group, and role to perform their tasks. In the previous chapter, you reviewed how you could quickly provide access using a pre-crafted policy that AWS manages.
As an AWS security professional, it is most likely that one of your duties will be to write and tune the policies that grant and restrict access to the resources held in the account and AWS Organizations. You need to have a comprehensive understanding of how to provide both access and denial to services for the users, groups, and roles in your account.
You should also be familiar with the tools that can show you whether you have provided the policies that your entities need or a set of permissions that is too large or too narrow for the duties that they are trying to perform. You will learn about the tool...