Skip to Content

Published 26/08/2018 – est. 3 minutes to read.

AWS (Amazon Web Services)

At Cyber Security Specialists, we do love AWS (other Cloud platforms are, of course, available). They are continuously adding new, awesome features and services for us to consume, making it even easier to get digital services online at pace.

And yet, as these services grow in popularity, it’s increasingly common to hear news stories about yet another organisation suffering a data breach and accidentally leaking sensitive data.  We feel a bit sorry for AWS in this regard because S3 Buckets are locked down by default, and it’s the AWS customer who can inadvertently make their Buckets public.  Because of all the bad news stories around S3 data breaches, we’ve had Clients question whether AWS is secure enough for them.  Our response is that AWS is a powerful and highly secure cloud environment, but it must be configured and maintained properly!

So, take the few simple steps below to secure S3:

  • Ensure your S3 Buckets are set to private, check your IAM policies and don’t set them to Public Read/Write!
  • Ensure your Buckets are encrypted by applying Default encryption policies.
  • If you are accessing your Bucket from a VPC, use a VPC endpoint to ensure that the Bucket accepts connections only from your VPC.
  • Enable Server Access logging to provide a full audit trail of S3 Bucket activity.

Now, how do you ensure that these Buckets remain secure and don’t end up being inadvertently made Public?  Easy, AWS has a number of services, such as AWS Config, Macie, and Trusted Advisor, that all have automated checks to scan for S3 Bucket changes to help address this problem.

In this blog, we’re going to focus on AWS Config – and the reasons we love it are that not only can AWS Config alert IT and Security Operations teams when a misconfiguration occurs (via email, SMS or Slack notification), but it can also proactively react and correct the misconfiguration for you with a Lambda function!

AWS Config enables continuous monitoring of your AWS resources, making it simple to assess, audit, and record resource configurations and changes.  There are a few dozen ‘AWS Managed Rules’ (or templates) within AWS Config, which include s3-bucket-public-read-prohibited & s3-bucket-public-write-prohibited, which, when enabled, will continuously monitor your private S3 Buckets for changes.

An overview of the architecture is below:

The steps to achieve this configuration are detailed below:

  1. Enable AWS Config to monitor Amazon S3 Bucket ACLs and policies for compliance violations.
  2. Create an IAM Role and Policy that grant a Lambda function permission to read S3 Bucket policies and send alerts through SNS.
  3. Create and configure a CloudWatch Events rule that triggers the Lambda function when AWS Config detects an S3 Bucket ACL or policy violation.
  4. Create a Lambda function that uses the IAM role to review S3 Bucket ACLs and policies, correct the ACLs, and notify your team of out-of-compliance policies.

Taking this approach can drastically reduce your risk of exposing sensitive personal information via an S3 Bucket.  If you want more detailed information on configuring the components above, read the excellent AWS Blog for step-by-step instructions.  What are you waiting for – secure your S3 Buckets now!

To evaluate your AWS config, conduct a cyber maturity audit, or discuss our services, connect directly with our technical team:

Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk

 

Contact us

Related Pages

Cyber Maturity Audit icon.

Cyber Maturity Audit

 

Learn more about a cyber maturity audit

Shield Icon.

Virtual Data Protection Officer

 

Learn more about the virtual data protection officer

Cyber Essentials Plus Icon.

Crest Penetration Testing

 

Learn more about crest penetration testing

CS360 ai icon.

CS360.ai Exposure Management Platform

 

Learn more about CS360.ai