A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with AWS KMS. Which policy should be used to enforce this?
Trap 1: Apply a bucket policy on each bucket denying PutObject without…
Bucket policies apply to individual buckets, not all buckets.
Trap 2: Enable AWS Config with the s3-bucket-server-side-encryption-enabled…
Config rules only detect non-compliant resources, they do not enforce.
Trap 3: Attach an IAM policy to each account's admin user requiring…
IAM policies are per-account and not inherited across accounts.
- A
Apply a bucket policy on each bucket denying PutObject without encryption
Why it fails: Bucket policies apply to individual buckets, not all buckets.
- B
Create an SCP at the root OU that denies s3:PutBucketEncryption unless encryption is set to AWS KMS
SCPs define the maximum permissions for all accounts in an organisation, so a root-level deny on s3:PutBucketEncryption unless the request specifies AWS KMS enforces encryption centrally. This satisfies the requirement to cover every account without per-account bucket policies.
- C
Enable AWS Config with the s3-bucket-server-side-encryption-enabled rule
Why it fails: Config rules only detect non-compliant resources, they do not enforce.
- D
Attach an IAM policy to each account's admin user requiring encryption
Why it fails: IAM policies are per-account and not inherited across accounts.