Control: AWS > CIS v1.4 > 2 - Storage > 2.01 - Simple Storage Service (S3) > 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual)
Configures auditing against a CIS Benchmark item.
Level: 2 (Not Scored)
Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.
Resource Types
This control targets the following resource types:
Policies
This control type relies on these other policies when running actions:
- AWS > CIS v1.4 > Maximum Attestation Duration
- AWS > CIS v1.4 > 2 - Storage > 2.01 - Simple Storage Service (S3) > 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual) > Attestation
- AWS > CIS v1.4
- AWS > CIS v1.4 > 2 - Storage > 2.01 - Simple Storage Service (S3) > 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual)
- AWS > CIS v1.4 > 2 - Storage
- AWS > CIS v1.4 > 2 - Storage > Maximum Attestation Duration
Category
In Your Workspace
Developers
- tmod:@turbot/aws-cisv1-4#/control/types/r020104
- tmod:@turbot/cis#/control/categories/v070501
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-cisv1-4#/control/types/r020104"
Get Controls
Control Type URI
Category URI
GraphQL
CLI