A Bucket Policy is a resource-based IAM policy attached to an Amazon S3 bucket. It defines which principals (AWS accounts, IAM users/roles, or everyone) can perform which actions (GetObject, PutObject, DeleteBucket, etc.) on the bucket and its objects.
s3:x-amz-server-side-encryption)aws:SecureTransport)A policy attached directly to an AWS resource (S3 bucket, SQS queue, KMS key) that defines who can access it, including principals from other accounts.
Protecting stored data by encrypting it on disk so that it cannot be read without the encryption key, even if the storage media is compromised.
When an AWS resource (S3 bucket, RDS instance, security group) is accessible from the internet, intentionally or accidentally, creating a potential security risk.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.