VPC with private subnets has no S3 endpoint

Severity
Low
Service
S3
Check ID
S3_NO_VPC_ENDPOINT

What this check finds

A VPC with private subnets reaches Amazon S3 over the public internet (via NAT/IGW) rather than a private S3 gateway endpoint. A gateway endpoint keeps S3 traffic on the AWS network, is free, and lets endpoint policies restrict which buckets are reachable — reducing the data-exfiltration path.

Passing looks like: Private S3 access via VPC gateway endpoint.

How to fix it

Create an S3 gateway endpoint and associate it with the VPC's private route tables.

AWS console

VPC → Endpoints → Create endpoint → AWS services → com.amazonaws.{region}.s3 (Gateway) → select the VPC and private route tables.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to VPC with private subnets has no S3 endpoint
FrameworkControls
NIST SP 800-53 Rev5 (Moderate)
  • CA-3 Information Exchange
  • SC-7 Boundary Protection
NIST Cybersecurity Framework 2.0
  • PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
ISO/IEC 27001:2022 Annex A
  • A.8.20 Networks security
  • A.8.21 Security of network services

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More S3 checks

All S3 checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only