S3 public access block
E459743
S3 public access block is a security feature in Amazon S3 that centrally controls and restricts public access to S3 buckets and objects to help prevent unintended data exposure.
Observed surface forms (1)
| Surface form | Occurrences |
|---|---|
| S3 Block Public Access | 1 |
Statements (41)
| Predicate | Object |
|---|---|
| instanceOf |
Amazon Web Services feature
ⓘ
S3 security feature ⓘ security control ⓘ |
| affects |
bucket ACL evaluation
ⓘ
bucket policy evaluation ⓘ object ACL evaluation ⓘ |
| appliesAtLevel |
account level
ⓘ
bucket level ⓘ |
| canBeSetTo |
allow controlled public access
ⓘ
block all public access ⓘ |
| canOverride |
bucket ACL public access
ⓘ
bucket policy public access ⓘ object ACL public access ⓘ |
| configurationScope |
AWS account
ⓘ
individual S3 bucket ⓘ |
| configuredVia |
AWS CLI
NERFINISHED
ⓘ
AWS CloudFormation NERFINISHED ⓘ AWS CloudTrail API calls ⓘ AWS Management Console NERFINISHED ⓘ AWS SDKs NERFINISHED ⓘ |
| controlsAccessTo |
S3 buckets
ⓘ
S3 objects ⓘ |
| defaultBehavior | does not automatically block all public access unless explicitly enabled ⓘ |
| documentationURL | https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html ⓘ |
| hasSetting |
BlockPublicAcls
ⓘ
BlockPublicPolicy ⓘ IgnorePublicAcls ⓘ RestrictPublicBuckets ⓘ |
| introducedFor | preventing accidental public S3 buckets ⓘ |
| monitoredBy | AWS CloudTrail NERFINISHED ⓘ |
| primaryGoal |
centrally restrict public access
ⓘ
prevent unintended public data exposure ⓘ |
| providedBy |
Amazon S3
NERFINISHED
ⓘ
Amazon Web Services NERFINISHED ⓘ |
| relatedTo |
S3 Block Public Access settings
ⓘ
S3 access control lists ⓘ S3 bucket policies ⓘ |
| securityBenefit |
helps enforce least privilege access
ⓘ
reduces risk of misconfigured public buckets ⓘ |
| supportsUseCase |
compliance with data protection requirements
ⓘ
organization-wide S3 access governance ⓘ |
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.
this entity surface form:
S3 Block Public Access