A financial institution requires strict access control for its data stored in Amazon S3. They have a policy that states data owners must explicitly approve every new access grant to their S3 buckets. Additionally, all S3 buckets must be private by default. Which access control mechanism, combined with appropriate IAM policies, best supports this requirement without creating overly permissive access or management overhead?
- AS3 Access Control Lists (ACLs) set to 'private' by default, with custom ACLs for specific users.
- BS3 Block Public Access settings enabled at the account level, and S3 bucket policies for granular access.
- CAWS Organizations Service Control Policies (SCPs) to deny public access and IAM roles for specific access.
- DIAM user policies with explicit `Allow` statements for each approved access to S3 resources.
Show answer & explanationAnswer & explanation
Correct answer: B. S3 Block Public Access settings enabled at the account level, and S3 bucket policies for granular access.
S3 Block Public Access settings, enabled at the account level, ensure that all S3 buckets are private by default and prevent accidental or malicious public exposure. S3 bucket policies then provide the necessary granular control to explicitly grant access only to approved identities or conditions, aligning with the data owner's explicit approval requirement. This combination enforces privacy by default and allows controlled exceptions.
Why the other options are wrong
- A. S3 ACLs are a legacy access control mechanism. While they can set private access, they are not as granular or flexible as bucket policies for complex conditions and managing access for many users/roles. Relying solely on ACLs for 'explicit approval' is cumbersome.
- C. SCPs are preventive guardrails that set maximum permissions; they can deny public access but do not grant specific access directly or manage the 'explicit approval' process effectively. IAM roles are part of the solution but SCPs alone don't fulfill the 'explicit approval' aspect.
- D. IAM user policies are identity-based. Managing individual IAM user policies for every S3 bucket and every access grant would lead to significant management overhead and potential for errors, especially as the number of users and buckets grows. S3 bucket policies are more efficient for resource-level control.
S3 Block Public Access & Bucket Policies
A combination of account-level S3 Block Public Access settings to ensure default privacy, and S3 bucket policies for explicit, granular access grants.
- S3 Block Public Access prevents public read/write access and public ACLs/policies.
- Enabled at account level, applies to all buckets in that account.
- S3 bucket policies define resource-based access permissions.
- Together, they enforce private by default while allowing controlled, explicit grants.
Memory trick: Block Public ensures private start, Bucket Policies play the granting part.