AWS SNS topic inventory

Document notification topics and their subscriptions.

Description

An SNS topic inventory records notification and event-delivery paths. The existence of a topic does not itself indicate a vulnerability.

Potential impact

An incomplete inventory can obscure owners and subscription destinations, or leave access policies unreviewed.

Remediation

Record each topic’s owning team and subscriptions, then check access policies, encryption, and tags.

Examples

The examples add identification tags without editing publishing-policy or subscription configuration. Check the effect of any tag-based IAM policies.

Before

hcl
resource "aws_sns_topic" "alerts" {
  name = "alerts-topic"
}

After

hcl
resource "aws_sns_topic" "alerts" {
  name = "alerts-topic"

  tags = {
    Service     = "alerting"
    Environment = "production"
  }
}

References