Amazon Macie produces findings. Interpreting the findings is how you develop an understanding into how your data is stored in your environment. For this job you configured your scan to use only the included managed data identifiers. In this section you will use the Findings menu option to view and filter the findings that were created by the two jobs you configured in Module 2. We will investigate some of the filter types and methods for applying them.
To create your first filter, we are going to include all findings that contain credentials and are tagged with a classification of public.
You should see a list of files, these files contain credentials and are tagged as public. By clicking one of the findings you will see the details panel on the right side appear. You can see all the details of the file. Scroll down and review the details of the file that resulted in the finding.
What S3 bucket is this file stored in?
Do you think this file is in the correct S3 bucket?
Are there files tagged as public stored in the incorrect buckets?
When you create a filter it can be an include filter or exclude filter. The default is an include filter. By clicking on the black circle next to the filter type you can change this.
Include filters are the same as EQUALS and Exclude filters are the same as NOT EQUALS
Our next filter will show us which files contain US Social Security numbers and if any of them are located in Public buckets.
Our example organization uses bucket tags to identify which buckets can be public so lets use that as the next filter criteria.
Can you find out which files contain credit card numbers?
Which buckets are those files stored in?
Are any of the files encrypted, are any unencrypted?
Click to expand for the solution
Create a filter using the Sensitive data detection type and filter on CREDIT_CARD_NUMBER
Click on a finding to display the finding details panel. The bucket name and encryption status can be found in the details panel.
Scroll down to find the object properties
An additional method to create a filter is to use the right hand details panel. Next to each of the details in the panel is a magnifying glass with a + that creates an include or equals filter and a magnifying glass with a - that creates an exclude or not equals filter.