More Info:

AWS S3 Buckets configuration changes should be monitored using CloudWatch alarms.

Risk Level

Medium

Address

Security

Compliance Standards

CISAWS, CBP, SOC2, NIST, AWSWAF, HITRUST, NISTCSF, PCIDSS

Triage and Remediation

Remediation

When you receive an S3 Bucket Changes Alarm, it means that there has been a change in the configuration of one of your S3 buckets. Here are the steps to remediate this issue in AWS Console:

  1. Log in to your AWS Management Console and navigate to the S3 service.

  2. Locate the bucket that triggered the alarm and click on it.

  3. Click on the “Permissions” tab and then click on “Bucket Policy”.

  4. Review the bucket policy to identify the misconfiguration that triggered the alarm.

  5. Once you have identified the misconfiguration, edit the bucket policy to correct the issue.

  6. After making the necessary changes, click on “Save”.

  7. Verify that the alarm has been cleared by checking the CloudWatch console.

  8. If the alarm persists, review the bucket policy again to ensure that all misconfigurations have been corrected.

  9. Once you have confirmed that the alarm has been cleared, you can close the ticket for this issue.

Additional Reading: