[KayD (accepted answer)]: You shouldn't use the wild card with resources, Right now it's opened widely for all the resources. ``` data "aws_iam_policy_document" "foo" { statement { effect = "Allow" actions = [ "cloudwatch:Describe*", "cloudwatch:Get*", "cloudwatch:List*", "sns:Subscribe", ] resources = ["resource-arn"] } } ``` If you change the resource's wild card to the list of arns of the resources, which will use this policy then checkov will not show this error anymore.

Context: Stack Overflow #67428658 (accepted answer, 3 votes, 1 answers): When run checkov for an Terraform resource scan, got this failed ``` Check: CKV_AWS_111: "Ensure IAM policies does not allow write access without constraints" FAILED for resource: aws_iam_policy_document.foo File: /data.tf:7-18 data "aws_iam_policy_document" "foo" { statement { effect = "Allow" actions = [ "cloudwatch:Describe*", "cloudwatch:Get*", "cloudwatch:List*", "sns:Subscribe", ] resources = ["*"] } } ``` From official document, found its introduction page. There is a Fix - Buildtime on the page, but how to refer it to use for my case? From its Resource Exposure on the page, I didn't fi