Control: AWS > CIS v1.4 > 2 - Storage > 2.01 - Simple Storage Service (S3) > 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual)
Configures auditing against a CIS Benchmark item.
Level: 2 (Not Scored)
Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.
Resource Types
This control targets the following resource types:
Primary Policies
The following policies can be used to configure this control:
- 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual)
- 2.01.04 - Ensure all data in Amazon S3 has been discovered, classified and secured when required. (Manual) > Attestation
Category
In Your Workspace
Developers
- tmod:@turbot/aws-cisv1-4#/control/types/r020104
- tmod:@turbot/cis#/control/categories/v070501
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-cisv1-4#/control/types/r020104"
Get Controls
Control Type URI
Category URI
GraphQL
CLI