AWSHow-To & HardeningRetrospectives

S3 Public Access Audit Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

Use this checklist to audit S3 public access across your AWS organization.

Account level

  • Account-level Block Public Access is enabled (all four settings) in every account.
  • An SCP prevents changing account-level Block Public Access.
  • Accounts that genuinely need public content are isolated and documented.

Bucket level

  • No bucket policies grant access to "Principal": "*" without restrictive conditions.
  • No ACLs grant AllUsers or AuthenticatedUsers access.
  • Object Ownership is set to "Bucket owner enforced" (ACLs disabled).
  • Buckets serving websites are private and fronted by CloudFront with Origin Access Control.

Cross-account access

  • IAM Access Analyzer is enabled with the organization as the zone of trust.
  • All external access findings have been reviewed and either archived with a reason or removed.
  • Access from third-party accounts uses roles with external IDs.

Data protection

  • Default encryption is enabled (SSE-S3 or SSE-KMS).
  • Sensitive buckets require TLS with an aws:SecureTransport deny.
  • Versioning and, where appropriate, Object Lock protect critical data.

Monitoring

  • AWS Config S3 rules are deployed in every region.
  • GuardDuty S3 Protection is enabled.
  • Policy and ACL changes alert the security team.

Process

  • Every bucket has an owner tag.
  • Findings older than 30 days are escalated.
s3 public access audit checklistS3 Block Public Access2018

More on this story