GuardDuty S3 Protection should be enabled
Description
This control checks whether GuardDuty S3 Protection is enabled. For a standalone account, the control fails if GuardDuty S3 Protection is disabled in the account. In a multi-account environment, the control fails if the delegated GuardDuty administrator account and all member accounts do not have S3 Protection enabled. S3 Protection enables GuardDuty to monitor object-level API operations and identify potential security risks for data within Amazon Simple Storage Service (Amazon S3) buckets. GuardDuty monitors threats against your S3 buckets.
Remediation
To enable GuardDuty S3 Protection, you need to configure the S3 Protection settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'S3 Protection'
- Enable 'S3 Protection'
- Configure the protection settings as needed
- Save the configuration
- Verify that S3 Protection is active