Description
Amazon S3 applies at least server-side encryption with S3-managed keys (SSE-S3) to new object uploads. Omitting BucketEncryption from a template does not leave new objects unencrypted. Specify a default that meets any additional requirements, such as use of a KMS key.
Potential impact
A default that differs from organizational requirements may not meet required key-policy or audit controls. Changing the bucket setting alone does not automatically change encryption on existing objects.
Remediation
Choose the required algorithm and key and configure BucketEncryption.ServerSideEncryptionConfiguration. For KMS, check key permissions for upload and read identities. Apply a bucket policy if a specific encryption method must be enforced, and assess and update existing objects separately.
Examples
New objects use SSE-S3 even in the original example. The revision is for a requirement to use a customer-managed KMS key; supply an available symmetric encryption KMS key ARN in the same Region as KmsKeyArn. A default encryption setting does not itself prohibit an upload request from specifying another encryption method.
Before
Resources:
S3Bucket:
Type: AWS::S3::Bucket
Properties:
BucketName: !Sub 'bucket-${AWS::Region}-${AWS::AccountId}'
After
Parameters:
KmsKeyArn:
Type: String
Resources:
S3Bucket:
Type: AWS::S3::Bucket
Properties:
BucketName: !Sub 'bucket-${AWS::Region}-${AWS::AccountId}'
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: aws:kms
KMSMasterKeyID: !Ref KmsKeyArn