Bucket Versioning Should Be Enabled
Ensures object versioning is enabled on storage buckets. Object versioning can help protect against the overwriting of objects or data loss in the event of a compromise.
Cloudanix
Ensures object versioning is enabled on storage buckets. Object versioning can help protect against the overwriting of objects or data loss in the event of a compromise.
Ensures object versioning is enabled on storage buckets. Object versioning can help protect against the overwriting of objects or data loss in the event of a compromise.
Ensures object logging is enabled on storage buckets. Storage bucket logging helps maintain an audit trail of access that can be used in the event of a security incident.
Ensures Storage bucket policies do not allow global write, delete, or read permissions. Storage buckets can be configured to allow the global principal to access the bucket via the bucket policy. This policy should be restricted only to known users or accounts.
Ensure that cloud Storage buckets have uniform bucket-level access enabled
Ensure that cloud Storage bucket Logs are not Publicly Accessible by setting "publicAccessPrevention" to "enforced".
Ensure that cloud Storage buckets are preferably encrypted using Customer Managed Keys (CMKs)
Ensure that cloud Storage buckets do not allow All Users to Write ("allUsers" must not have "WRITER" roles)
Ensure that cloud Storage buckets do not allow All Authenticated Users to Write ("allAuthenticatedUsers" must not have "WRITER" roles)
Ensure that cloud Storage buckets do not allow All Users to have Ownership ("allUsers" must not have "OWNER" roles)
Ensure that cloud Storage buckets do not allow All Authenticated Users Ownership ("allAuthenticatedUsers" must not have "OWNER" roles)
Ensure that cloud Storage buckets do not allow All Users to Read ("allUsers" must not have "READER" roles)
Ensure that cloud Storage buckets do not allow All Authenticated User Reads ("allAuthenticatedUsers" must not have "READER" roles)
Ensure that cloud Storage buckets following a DNS-compliant naming scheme, which avoid the use of a period i.e. "."
Storage Buckets should have a retention policy defined to add an extra layer of protection, for instance, to assist recovery in case of an accidental deletion.
Buckets should have Lifecycle Rules Configured for smooth operation, like deletion of old non-concurrent objects.
List all the buckets that have website configuration (this is an informational rule only)
Buckets must have a Retention Policy Configured along with a Retention Period, that is specified by the User (must be greater than 0)
Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.
Book a DemoCLOUDANIX
Explore guides, checklists, and blogs that simplify cloud security and help you secure your infrastructure.
Real-world success stories where Cloudanix helped organizations secure their cloud infrastructure. Watch how we made a difference across ind…
Read Case Studies
Understand what Cloud Security Posture Management (CSPM) is and how it automates security and compliance across cloud environments.
Read moreUnderstand how CASB, CSPM, and SIEM work together to enhance your cloud security posture and ensure better governance.
Read the blogIn-depth assessment of cloud environment for security, compliance, and optimization. Identify vulnerabilities, ensure data protection, and o…
Read the blogCloud environments are getting more complex and dynamic day by day, making it difficult to gain complete visibility into all assets and thei…
Read the blogCloudanix offers you a single dashboard to secure your workloads. Learn how to set up Cloudanix for your cloud platform from our documentati…
Take a lookA complete history of changes, improvements, and fixes for Cloudanix. Subscribe to get notified about the latest updates.
View Changelog