Accepted Risks Documentation - Korr
Risk ID | Risk Description | Justification | Mitigation Controls | Risk Owner | Review Date | Status |
---|---|---|---|---|---|---|
AR-001 | Use of service account for automated AWS operations | Service account required for automated scanning and reporting via Modal deployment. Account used for accessing S3 bucket data and generating compliance reports. | - Limited IAM permissions following principle of least privilege - Regular credential rotation - Access logging and monitoring - Access restricted to specific S3 buckets and operations |
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article