AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium
A company uses AWS Organizations and has a multi-account strategy. They want to ensure that no AWS account within their organization can ever create an Amazon S3 bucket that is publicly accessible, regardless of any IAM policies or S3 bucket policies applied at the account level. This restriction must apply to all current and future accounts. Which AWS Organizations feature should be implemented to enforce this control?
- AImplement an AWS Service Control Policy (SCP) at the organizational root or an appropriate OU.
- BApply an IAM policy to the root user of each AWS account restricting public S3 bucket creation.
- CUse AWS Config rules to detect and remediate publicly accessible S3 buckets.
- DConfigure S3 Block Public Access settings at the account level for every AWS account.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement an AWS Service Control Policy (SCP) at the organizational root or an appropriate OU.
AWS Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to centrally manage permissions for all accounts in your organization. They act as guardrails, setting maximum available permissions for all IAM users and roles in affected accounts, including the root user. An SCP can explicitly deny actions that create publicly accessible S3 buckets.
Why the other options are wrong
- B. Applying IAM policies to root users is not scalable across a multi-account organization and does not prevent other IAM users/roles from creating public buckets if their policies allow it. SCPs provide a stronger, centralized control.
- C. AWS Config rules detect non-compliance but do not prevent the creation of public S3 buckets. They are reactive, not preventative, and remediation might be too late for sensitive data.
- D. S3 Block Public Access settings are effective at the account level, but they need to be configured for each account individually and new accounts might not have it enabled by default. An SCP provides a centralized, preventative control.
AWS Service Control Policies (SCPs)
SCPs are JSON policies that specify the maximum permissions for all IAM users and roles in an AWS account, including the root user.
- Part of AWS Organizations.
- Preventative guardrails across multiple accounts.
- Do not grant permissions; they filter them.
Memory trick: Organization's SCPs block bad S3 buckets.