Access Logging Enabled
Check S3 bucket access logging is enabled on the CloudTrail S3 bucket
Check S3 bucket access logging is enabled on the CloudTrail S3 bucket
Check the S3 bucket logs are not publicly accessible
Check if S3 buckets have default encryption (SSE) enabled or use a bucket policy to enforce it.
Check if S3 buckets have object versioning enabled
Check if S3 buckets have secure transport policy
Check if S3 buckets have policies which allow public WRITE access
Ensure S3 buckets do not allow WRITE access to AWS authenticated users through S3 ACLs.
Ensure that your AWS S3 buckets are using DNS-compliant bucket names.
Ensure AWS S3 buckets have the MFA Delete feature enabled.
Ensure AWS S3 buckets do not allow public access via bucket policies.
Ensure that Amazon S3 buckets are encrypted with customer-provided AWS KMS CMKs.
Ensure Amazon S3 buckets have lifecycle configuration enabled for security and cost optimization purposes.
Ensure S3 buckets with website configuration enabled are regularly reviewed (informational).
Ensure that AWS S3 buckets use Object Lock for data protection and/or regulatory compliance.
Ensure that Amazon S3 buckets use Transfer Acceleration feature for faster data transfers.
Ensure that your AWS S3 buckets are not publicly exposed to the Internet.
Ensure S3 buckets do not allow FULL_CONTROL access to AWS authenticated users via S3 ACLs.
Ensure AWS S3 buckets do not allow public READ access.
Ensure S3 buckets do not allow READ access to AWS authenticated users through ACLs.
Ensure AWS S3 buckets do not allow public READ_ACP access.
Ensure AWS S3 buckets do not allow READ_ACP access to AWS authenticated users using ACLs.
Ensure AWS S3 buckets do not allow public WRITE_ACP access.
Ensure AWS S3 buckets do not allow WRITE_ACP access to AWS authenticated users using ACLs.
Ensure AWS S3 buckets enforce Server-Side Encryption (SSE).
If you are not yet convinced to sign up with Cloudanix, that's not a problem. We recommend you use a comprehensive checklist which your team can use to perform a manual assessment of your workload.