Amazon_S3_17

Ensure S3 bucket should not host static website

Description

On a static website, individual webpages include static content. To host a website, your bucket must have public read access. It is intentional that everyone in the world will have read access to this bucket. It is recommended that the bucket policy or access control list (ACL) applied to the S3 bucket to prevent public access to the bucket content.

Remediation

Perform the following to disable static website hosting on your S3 bucket

  1. Sign in to the AWS Management Console.
  2. Navigate to S3 dashboard at https://console.aws.amazon.com/s3/.
  3. Select the S3 bucket that you want to examine and click the Properties tab from the S3 console.
  4. Check for Static website hosting if enabled then click on the bucket hosting checkbox.
  5. Click on&nbsp

Service

S3

Severity

Low

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!