A global media company uses AWS Organizations to manage multiple accounts. They want to ensure that all data stored in Amazon S3 buckets across all accounts is encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS) and that encryption cannot be disabled for any new or existing S3 objects. They also need to restrict access to S3 buckets only from specific VPC endpoints. What is the MOST efficient way to enforce these security requirements across all organizational accounts?
- AUse Service Control Policies (SCPs) to deny S3 PutObject and CreateBucket operations that do not specify SSE-KMS, and deny access from non-specified VPC endpoints.
- BImplement AWS CloudFormation StackSets to deploy S3 bucket policies and SCPs to enforce KMS encryption.
- CCreate an AWS Lambda function that monitors S3 bucket creation and automatically applies the required encryption, and VPC endpoint policies.
- DApply S3 bucket policies to each S3 bucket in every account and use AWS Config rules.
Show answer & explanationAnswer & explanation
Correct answer: A. Use Service Control Policies (SCPs) to deny S3 PutObject and CreateBucket operations that do not specify SSE-KMS, and deny access from non-specified VPC endpoints.
SCPs are the most efficient way to enforce these strict, organization-wide security requirements. They provide guardrails that prevent accounts from performing disallowed actions, ensuring that KMS encryption for S3 is always used and access is restricted to specific VPC endpoints, without requiring individual resource-level configurations.
Why the other options are wrong
- B. CloudFormation StackSets can deploy policies, but SCPs provide a stronger, preventative control at the organizational level that cannot be overridden by individual accounts.
- C. Lambda functions are reactive; they would remediate after a non-compliant bucket is created, rather than preventing it, and would be complex to manage for VPC endpoint enforcement.
- D. Applying individual bucket policies is manual and prone to error, not scalable for 'all accounts'. AWS Config rules detect non-compliance but don't prevent it.
Service Control Policies (SCPs)
AWS Organizations policies that specify the maximum permissions for all IAM entities in an account, acting as guardrails for security and compliance.
- Apply to all IAM users and roles in affected accounts.
- Cannot grant permissions; only restrict them.
- Preventative controls that cannot be overridden by account administrators.
Memory trick: SCPs are the security guards at the organizational gate, preventing unauthorized actions.