S3 bucket access logging needs review

Collect the required S3 request records and check delivery and retention.

Description

S3 server access logs help investigate requests to a bucket and their response status. Without retained request records, unusual access or operational errors may be harder to analyze.

Server access logs are delivered on a best-effort basis, and some records may be delayed or missing. They do not replace access controls or provide a complete audit of every request.

Potential impact

  • Evidence needed to investigate requests or errors may be missing.
  • Poor log access and retention controls may expose request information.

Remediation

Collect the required access logs through LoggingConfiguration. For an S3 destination, prepare a separate bucket in the same account and Region and grant log delivery permissions. Restrict log access and retention, then verify collection after sending requests, allowing for delivery delays.

Examples

AccessLogBucketName is the actual destination bucket name. Prepare the bucket and log delivery service permissions separately. Versioning and access logging serve different purposes.

Before

yaml
Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      VersioningConfiguration:
        Status: Enabled

No server access log destination is configured. Also check whether another audit mechanism captures the required records.

After

yaml
Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      VersioningConfiguration:
        Status: Enabled
      LoggingConfiguration:
        DestinationBucketName: !Ref AccessLogBucketName
        LogFilePrefix: loga/

Server access logs are stored in a separate S3 bucket. This does not guarantee immediate recording of every request.

References