Control: AWS > CIS v6.0 > 3 - Storage > 3.01 - Simple Storage Service (S3) > 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
Configures auditing against a CIS Benchmark item.
Level: 2
Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.
Resource Types
This control targets the following resource types:
Policies
This control type relies on these other policies when running actions:
- AWS > CIS v6.0 > Maximum Attestation Duration
- AWS > CIS v6.0 > 3 - Storage > 3.01 - Simple Storage Service (S3) > 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary > Attestation
- AWS > CIS v6.0 > 3 - Storage > Maximum Attestation Duration
- AWS > CIS v6.0
- AWS > CIS v6.0 > 3 - Storage > 3.01 - Simple Storage Service (S3) > 3.01.03 - Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
- AWS > CIS v6.0 > 3 - Storage > 3.01 - Simple Storage Service (S3)
Category
In Your Workspace
Developers
- tmod:@turbot/aws-cisv6-0#/control/types/r030103
- tmod:@turbot/cis#/control/categories/v070501
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-cisv6-0#/control/types/r030103"
Get Controls
Control Type URI
Category URI
GraphQL
CLI