High
GuardDuty
Regional
GuardDuty S3 Protection should be enabled
PCI DSS v4.0.1PCI DSS v11.5.1
Description
Ensures GuardDuty S3 Protection is enabled across all accounts to monitor object-level API operations and identify potential security risks in S3 buckets.
Remediation
To enable GuardDuty S3 Protection, you need to configure the S3 Protection settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'S3 Protection'
- Enable 'S3 Protection'
- Configure the protection settings as needed
- Save the configuration
- Verify that S3 Protection is active
Compliance
PCI DSS v4.0.1PCI DSS v11.5.1