Step 6 - Create an IAM DLP Policy
- Click Services and select IAM.
- Select Policies and click Create Policy.
- Click the JSON tab.
- Copy and paste the policy information.
{ "Statement": [ { "Action": [ "iam:GetUser", "iam:ListUsers", "iam:GetGroup", "iam:ListGroups", "iam:ListGroupsForUser", "s3:ListAllMyBuckets", "s3:GetBucketNotification", "s3:GetObject", "s3:GetBucketLocation", "s3:PutBucketNotification", "s3:PutObject", "s3:GetObjectAcl", "s3:GetBucketAcl", "s3:PutBucketAcl", "s3:PutObjectAcl", "s3:DeleteObject", "s3:ListBucket", "sns:CreateTopic", "sns:SetTopicAttributes", "sns:GetTopicAttributes", "sns:Subscribe", "sns:AddPermission", "sns:ListSubscriptionsByTopic", "sqs:CreateQueue", "sqs:GetQueueUrl", "sqs:GetQueueAttributes", "sqs:SetQueueAttributes", "sqs:ChangeMessageVisibility", "sqs:DeleteMessage", "sqs:ReceiveMessage" "cloudtrail:DescribeTrails" ], "Effect": "Allow", "Resource": "*", "Sid": "LookoutCASBAwsDlpPolicy" } ], "Version": "2012-10-17" }
- Click Review Policy.
- Name the policy lookout-api-policy and click Create Policy.