Skip to main content


Ensure the bucket Access Control List (ACL) does not grant 'Everyone' READ permission [list S3 objects]


The S3 bucket ACL gives 'Everyone' permission to list objects, which allows anyone to list the bucket contents. It is best practice to restrict READ permission to only principals who require it.

Note: S3 buckets created with the default/recommended AWS settings have ACLs turned off and are therefore compliant with this policy.


Perform the following to revoke READ permission for 'Everyone':

  1. Sign in to the AWS Management Console.
  2. Select Services.
  3. Select S3.
  4. Select the bucket to change.
  5. Navigate to Permissions.
  6. Navigate to Access Control List and select Edit.
  7. Against Everyone (public access), clear 'List' under Objects.
  8. Select Save changes.
  9. Repeat steps 4-8 for each bucket requiring updated permissions.