Accepted Risks

Created by Venkat Pothamsetty, Modified on Mon, 30 Jun at 12:53 PM by Venkat Pothamsetty


Accepted Risks Documentation - Korr

Risk IDRisk DescriptionJustificationMitigation ControlsRisk OwnerReview DateStatus
AR-001Use of service account for automated AWS operationsService account required for automated scanning and reporting via Modal deployment. Account used for accessing S3 bucket data and generating compliance reports.- Limited IAM permissions following principle of least privilege
- Regular credential rotation
- Access logging and monitoring
- Access restricted to specific S3 buckets and operations

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article