S3 bucket policy should deny HTTP requests

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Description

At the Amazon S3 bucket level, you can configure permissions through a bucket policy to make objects accessible only through HTTPS. By default, Amazon S3 allows both HTTP and HTTPS requests. To enforce HTTPS-only access, you must explicitly deny HTTP requests. Bucket policies allowing HTTPS but not explicitly denying HTTP do not comply with this security recommendation. Implementing such a policy helps safeguard data by ensuring only encrypted data transfers using HTTPS, thereby enhancing security.

Remediation

For instructions on configuring your Amazon S3 bucket policy to require HTTPS, refer to the Amazon S3 Developer Guide and the IAM User Guide.