Skip to content

Securing your S3 buckets: essential best practices

Security best practices guide for Amazon S3: encryption, access control, versioning and monitoring to protect your data.

Updated on 14 August 2023

Protect your data in the cloud

Amazon S3 stores billions of objects for millions of customers. Its durability is 99.999999999% (eleven nines), which means your data will not be lost. However, the security of your data depends on your configuration. A misconfigured S3 bucket can expose sensitive data. This guide covers the essential best practices for securing your S3 buckets.

Block public access

The first measure is to enable S3 Block Public Access at the AWS account level. This setting prevents any attempt to make a bucket or object public, even if a bucket policy or ACL allows it. Go to the S3 console, click “Block Public Access settings for this account” and enable all four options.

This measure protects against the configuration mistakes that are the most common cause of data leaks on S3. The high-profile cases of exposed data on S3 are almost always due to public access enabled by mistake.

Encrypt your data

Since January 2023, S3 encrypts all new objects by default with SSE-S3. This encryption protects data at rest on Amazon’s disks. For additional control, use SSE-KMS, which lets you manage your own encryption keys through AWS Key Management Service.

SSE-KMS offers additional advantages: automatic key rotation, logging of every key use in CloudTrail and the ability to revoke access by disabling the key. For the most sensitive data, client-side encryption (CSE) encrypts the data before sending it to S3.

Enable versioning

Versioning keeps every version of each object. An accidental deletion does not actually remove the object but creates a delete marker. You can restore any previous version. An unintended overwrite is reversible.

Combine versioning with lifecycle rules to control costs. Old versions can be moved to S3 Glacier after 30 days and deleted after 90 days. This approach offers protection against mistakes while keeping storage costs under control.

Control access with policies

Bucket policies and IAM policies control who can access which objects and with which permissions. Apply the principle of least privilege: each user and each service has only the permissions strictly needed.

Use conditions in policies to restrict access by IP address, by VPC or by protocol (HTTPS only). The aws:SecureTransport condition enforces the use of HTTPS for all requests, which protects data in transit.

Monitor with CloudTrail and S3 Access Logs

AWS CloudTrail records every API call to S3: bucket creation, policy changes, object access. These logs are essential for auditing and detecting suspicious activity.

S3 Server Access Logging records every request to a bucket: who accessed which object, when and from which IP address. These logs complement CloudTrail with more detailed information about data access.

LCMH supports businesses in securing their AWS infrastructure.

For a complete guide on secure web hosting, read our article on hosting static websites on AWS.


Sources

  1. AWS, Security Best Practices for Amazon S3. docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
  2. AWS, S3 Block Public Access. docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html
  3. AWS, S3 Default Encryption. docs.aws.amazon.com/AmazonS3/latest/userguide/default-bucket-encryption.html

Frequently asked questions

Is S3 encrypted by default?
Yes. Since January 2023, all new objects stored in S3 are encrypted by default with SSE-S3 (server-side encryption with keys managed by S3). You can also use SSE-KMS to manage your own encryption keys through AWS KMS.
How do you prevent accidental public access to an S3 bucket?
Enable S3 Block Public Access at the AWS account level. This setting blocks any attempt to make a bucket or object public, even if a policy allows it. It is the most effective measure against accidental data leaks.
Should you enable versioning on S3?
Yes. Versioning protects against accidental deletions and overwrites. Each change creates a new version of the object. You can restore any previous version. Combine versioning with lifecycle rules to control storage costs.

Related Articles