Medium
CloudFront
CloudFront distributions should use origin access control
NIST
Description
This control checks whether an Amazon CloudFront distribution with an Amazon S3 origin has origin access control (OAC) configured. The control fails if OAC isn't configured for the CloudFront distribution.
Remediation
To configure OAC for a CloudFront distribution with S3 origins, follow these steps:
Steps
- Open the Amazon CloudFront console.
- Select the distribution you want to modify.
- Go to the 'Origins and Origin Groups' tab.
- Select the origin and choose 'Edit'.
- In the 'Origin Access Control' section, select the appropriate OAC configuration.
- Save the changes.
Compliance
NIST