Review S3 bucket default encryption policy

Check that S3 default encryption meets the organization’s algorithm and key-management requirements.

Description

Amazon S3 applies at least server-side encryption with S3-managed keys (SSE-S3) to new object uploads. Omitting BucketEncryption from a template does not leave new objects unencrypted. Specify a default that meets any additional requirements, such as use of a KMS key.

Potential impact

A default that differs from organizational requirements may not meet required key-policy or audit controls. Changing the bucket setting alone does not automatically change encryption on existing objects.

Remediation

Choose the required algorithm and key and configure BucketEncryption.ServerSideEncryptionConfiguration. For KMS, check key permissions for upload and read identities. Apply a bucket policy if a specific encryption method must be enforced, and assess and update existing objects separately.

Examples

New objects use SSE-S3 even in the original example. The revision is for a requirement to use a customer-managed KMS key; supply an available symmetric encryption KMS key ARN in the same Region as KmsKeyArn. A default encryption setting does not itself prohibit an upload request from specifying another encryption method.

Before

yaml
Resources:
  S3Bucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: !Sub 'bucket-${AWS::Region}-${AWS::AccountId}'

After

yaml
Parameters:
  KmsKeyArn:
    Type: String
Resources:
  S3Bucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: !Sub 'bucket-${AWS::Region}-${AWS::AccountId}'
      BucketEncryption:
        ServerSideEncryptionConfiguration:
          - ServerSideEncryptionByDefault:
              SSEAlgorithm: aws:kms
              KMSMasterKeyID: !Ref KmsKeyArn

References