S3 Public Access Audit Checklist
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
Use this checklist to audit S3 public access across your AWS organization.
Account level
- Account-level Block Public Access is enabled (all four settings) in every account.
- An SCP prevents changing account-level Block Public Access.
- Accounts that genuinely need public content are isolated and documented.
Bucket level
- No bucket policies grant access to
"Principal": "*"without restrictive conditions. - No ACLs grant
AllUsersorAuthenticatedUsersaccess. - Object Ownership is set to "Bucket owner enforced" (ACLs disabled).
- Buckets serving websites are private and fronted by CloudFront with Origin Access Control.
Cross-account access
- IAM Access Analyzer is enabled with the organization as the zone of trust.
- All external access findings have been reviewed and either archived with a reason or removed.
- Access from third-party accounts uses roles with external IDs.
Data protection
- Default encryption is enabled (SSE-S3 or SSE-KMS).
- Sensitive buckets require TLS with an
aws:SecureTransportdeny. - Versioning and, where appropriate, Object Lock protect critical data.
Monitoring
- AWS Config S3 rules are deployed in every region.
- GuardDuty S3 Protection is enabled.
- Policy and ACL changes alert the security team.
Process
- Every bucket has an owner tag.
- Findings older than 30 days are escalated.