Onam Security

Access mapping

How DSPM shows who and what can reach a data store: public grants, other accounts, access seen in audit events, encryption and keys, and attack paths.

Each store carries five views of access. They answer different questions, and the combination is what turns a label into a priority.

1. Public exposure

A store is treated as public only when an actual grant makes it so. For S3 the engine combines three signals, each suppressed by the matching public-access block setting:

  • the provider's own policy verdict that the bucket is public,
  • an ACL grant to all users or to all authenticated users,
  • a bucket-policy statement with a wildcard principal.

A bucket with no public-access block configured but no public grant is not reported as public. For databases, the provider's publicly-accessible flag is used.

2. Other accounts

Bucket policies are read statement by statement. An Allow to a principal in an account other than the store's own is a finding:

GrantSeverity
Write, delete or modify from another accountCritical
Policy-related actions from another accountHigh
Read from another accountHigh — raised to critical if object reads on the bucket were seen in the last 24 hours

On AWS, Lake Formation grants are also checked for broad defaults and wildcard administrative grants.

3. Observed access

From cloud audit events over the last 30 days, grouped per store: the number of accesses, the number of distinct principals, the operations used and the time of last access. This is what actually happened, which is often narrower than what policy allows — and occasionally wider than anyone expected.

4. Encryption and keys

The Encryption engine reads DSPM's labels and flags sensitive data that is unencrypted (critical) or protected only by a provider-managed key (high). Key policies are parsed separately for wildcard principals, other accounts and grants. See Exposure, encryption and residency.

5. Attack paths

DSPM writes three facts about every store to the security graph — its top classification, whether it is public, and whether it is unencrypted at rest. The attack-path engine uses them to confirm paths whose last step reaches a sensitive store, so a chain of findings that ends at customer data is scored above one that ends at a scratch bucket. Each account also gets a count of the PII stores in it.

What access mapping does not do

It does not compute, for each store, the complete list of identities whose effective permissions allow a read. That is an identity question, answered per principal in CIEM on the same graph. CIEM findings that concern data access are merged into the DSPM findings view.