Condition: for example, the source IP address, the hour of the day, etc
Action: for example read a bucket, write in a bucket, etc
Resources; The AWS resource, specified as Amazon Resource Name (ARN)
Effect: Allow / Deny
Service: AWS service, for example EC2 or S3
-