S3 bucket with versioning enabled does not have MFA delete configured

Severity
Low
Service
S3
Check ID
S3_MFA_DELETE_DISABLED

What this check finds

MFA delete prevents accidental or malicious permanent deletion of object versions. When enabled, delete operations on versioned objects require an MFA token in addition to valid AWS credentials, making ransomware and insider-threat scenarios significantly harder. CIS v5.0 §2.1.2.

Passing looks like: S3 MFA delete configured.

How to fix it

Enable MFA delete on the versioned bucket. This requires root account credentials and cannot be done via the console.

AWS CLI

  1. aws s3api put-bucket-versioning --bucket BUCKET_NAME --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa "SERIAL_NUMBER TOKEN_VALUE"
  2. Note: the root MFA serial number and a current token are required.

Names in capitals are placeholders for your own resource. Review a command before you run it.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to S3 bucket with versioning enabled does not have MFA delete configured
FrameworkControls
CIS AWS Foundations Benchmark v5.0.0
  • 2.1.2 Ensure MFA Delete is enabled on S3 buckets
PCI-DSS v4.0.1
  • 10.3 Audit logs are protected from destruction and unauthorized modifications
HIPAA Security Rule
  • 164.312(c)(1) Implement policies to protect ePHI from improper alteration or destruction
NIST SP 800-53 Rev5 (Moderate)
  • AU-9 Protection of Audit Information
  • CP-9 System Backup
  • SI-12 Information Management and Retention
NIST Cybersecurity Framework 2.0
  • PR.DS-11 Backups of data are created and protected
  • PR.PS-04 Log records are generated for monitoring
ISO/IEC 27001:2022 Annex A
  • A.5.28 Collection of evidence
  • A.5.30 ICT readiness for business continuity
  • A.5.33 Protection of records
  • A.8.10 Information deletion
  • A.8.13 Information backup
  • A.8.15 Logging

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More S3 checks

All S3 checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only