AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium

A security team needs to enforce that all Amazon S3 buckets across multiple AWS accounts in an organization are configured with default encryption using AWS Key Management Service (KMS) with customer-managed keys (CMKs). How can a DevOps engineer implement this compliance requirement at scale and prevent future non-compliant buckets from being created?

  1. AApply an S3 bucket policy to all new buckets that denies uploads if default encryption is not KMS.
  2. BImplement an AWS Organizations Service Control Policy (SCP) that restricts the s3:PutBucketEncryption action to only allow KMS CMK usage.
  3. CCreate an AWS Config rule to detect non-compliant buckets and remediate them using a Lambda function.
  4. DUse Amazon Macie to identify buckets without KMS encryption and then manually reconfigure them.
Show answer & explanation

Correct answer: B. Implement an AWS Organizations Service Control Policy (SCP) that restricts the s3:PutBucketEncryption action to only allow KMS CMK usage.

An AWS Organizations Service Control Policy (SCP) is the most effective way to prevent the creation of non-compliant resources across an entire organization. By denying s3:PutBucketEncryption unless it specifies a KMS CMK, new buckets will be forced to comply with the encryption standard from inception.

Why the other options are wrong

  • A. S3 bucket policies apply at the bucket level. It's difficult to apply them to *all* new buckets automatically and proactively prevent their creation.
  • C. AWS Config can detect and remediate, but it's reactive. SCPs are proactive and prevent non-compliance.
  • D. Amazon Macie is for data discovery and classification, not for enforcing bucket configuration policies or preventing non-compliant resource creation.

SCP for S3 Encryption Enforcement

A Service Control Policy (SCP) can be used within AWS Organizations to enforce S3 bucket encryption standards (e.g., requiring KMS CMKs) by denying actions that create or modify buckets without the specified encryption.

  • SCPs apply to accounts or OUs, not specific resources.
  • They are preventative controls, denying actions that violate policy.
  • Cannot grant permissions; only restrict what IAM policies can grant.

Memory trick: To 'control' 'all' 'buckets', use the 'organizational' 'policy'.

More Security and Compliance questions