Amazon S3 bucket inventory

Track object-storage ownership and data purpose.

Description

AWS::S3::Bucket declares an object-storage bucket. Its presence belongs in the asset inventory and does not itself indicate public exposure or a vulnerability.

Potential impact

An omitted bucket can be missed during access-policy, data-retention, and cost reviews.

Remediation

Record the bucket’s owner and purpose, and check Block Public Access, bucket policies, versioning, and encryption-key selection.

Examples

Choose an available unique bucket name. Both configurations encrypt new objects; the second selects versioning and SSE-KMS. Changing default encryption does not re-encrypt existing objects.

Before

yaml
Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: jenkins-artifacts

After

yaml
Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: jenkins-artifacts
      VersioningConfiguration:
        Status: Enabled
      BucketEncryption:
        ServerSideEncryptionConfiguration:
          - ServerSideEncryptionByDefault:
              SSEAlgorithm: aws:kms

References