A ACME Payments · Controls Review Signed in as george@acme

Controls Review - ACME Payments Platform

Document Information


This document is a fictional (but realistic) controls review process for the ACME Payment Platform which is part of the equally fictional ACME Corp. It is designed to show how a controls review document can be combined with live cloud service data in an attestation workflow.

The document allows switching between two different applications and demo users — select George or Ringo in the top right to see their respective applications.

By default this is showing realistic demo data. If you check “Live Data” in the top right you will see the discovery panes refresh with data from one of two live AWS accounts. Note these are real accounts but have a different mix of services running in them, so for the account linked to Ringo a number of panes correctly report no services found.

If you would like a demo of this with a live AWS demo environment please drop us an email at support@cloudsandlight.com and we’ll be happy to help you set up a LightPane account and show you how to host and manage your own document with live embedded data from AWS, GCP or Azure.


This is the annual controls recertification process for the S3 Data Security Controls (ACME-DSC-S3-001) as applied to the application ACME Payment Platform (ACME-INV: 0076193).

This review is required to be completed annually by the service owner for the stated application.

This document defines the mandatory data security controls and standards for all Amazon S3 storage used within ACME Corporation's AWS environments. It forms part of the ACME Corp Data Security Controls and Standards framework (ACME-DSC-001) and must be applied to all applications that utilise S3 for data storage, transfer, or archival. Compliance with these controls is required for all production workloads and must be reviewed and attested annually by the responsible application owner.

S3 Security Controls

The following controls are mandatory for all Amazon S3 buckets within ACME Corporation AWS accounts. Controls are categorised by domain and each carries a severity classification. Non-compliance with any High severity control must be remediated within 14 days of discovery or an exception must be formally raised with the Cloud Security Team.

For any control breaks which are rated as Critical you should contact the ACME Infosec Helpdesk immediately to notify them of a Critical Control Failure. Failure to do this may result in disciplinary action.

For this review you are required to analyze the live data from your application and compare it with the control requirement. If you believe the evidence shows you are in compliance with the control you must record this for each section.

For any area where you are not in compliance with the control you are required to submit a Remediation Plan in the ACME Corp Service Now Portal within 5 days of this review starting. The remediation plan should have an end date in line with the control severity.

Once the review is completed an immutable copy of both the standards and the live S3 environment for the application "ACME Payment Platform (ACME-INV: 0076193)" together with the service owners attestation of compliance with the standards will be saved in the compliance audit vault. These documents are reviewed frequently and may be made available to external auditors and regulators.

ACME Corp S3 Standards

Document Reference ACME-DSC-S3-001
Classification Internal - Restricted
Current Version 15 January 2026
Owner Cloud Security Team

Revision History

Version Date Author Summary
1.4 15 Jan 2026 M. Fischer Added GDPR cross-border data transfer controls for EU regions
Reviewed ByReview DateChange TypeSections Modified
K. Van der Berg10 Jan 2026Minor update2.4 Replication & Resilience, 2.5 Lifecycle

1.3 02 Aug 2025 M. Fischer Updated encryption requirements for KMS key rotation policy
Reviewed ByReview DateChange TypeSections Modified
S. Johansson28 Jul 2025Minor update2.3 Encryption Standards

1.2 18 Mar 2025 S. Johansson Annual review — added PII tagging requirement
Reviewed ByReview DateChange TypeSections Modified
M. Fischer12 Mar 2025Annual review2.2 Tagging Standards, 2.5 Lifecycle

1.1 22 Sep 2024 M. Fischer Added S3 Object Lock guidance for compliance buckets
Reviewed ByReview DateChange TypeSections Modified
K. Van der Berg18 Sep 2024Minor update2.5 Lifecycle & Retention

1.0 05 Feb 2024 S. Johansson First published version — approved for production use
Reviewed ByReview DateChange TypeSections Modified
M. Fischer, K. Van der Berg01 Feb 2024Initial releaseAll sections

0.9 12 Dec 2023 S. Johansson Final draft - submitted for approval
Reviewed ByReview DateChange TypeSections Modified
Cloud Security Board08 Dec 2023Final draft reviewAll sections

Annual Approval History

Approval Year Approved By Date Version Approved
2025 Dr. H. Brandt, CISO 22 Mar 2025 1.2
Approval NotesReview ScopeNext Review DueStatus
Approved with new PII tagging requirement. All applications must comply by 30 Jun 2025.Full annual reviewMarch 2026Current

2024 Dr. H. Brandt, CISO 15 Feb 2024 1.0
Approval NotesReview ScopeNext Review DueStatus
Initial production approval. Replaces interim S3 guidelines (ACME-TMP-S3-2023).Full initial reviewFebruary 2025Superseded

2023 P. Almeida, Head of Infrastructure 20 Dec 2023 0.9 (Draft)
Approval NotesReview ScopeNext Review DueStatus
Conditional approval of final draft for limited pilot use pending formal v1.0 release.Draft reviewFebruary 2024Superseded



Annual Review - S3 Access Controls

Reviewer: George (george@acme) Application: ACME Payment Platform ACME-INV: 0076193 AWS account: · eu-west-2

Management System Tags Must be set for Every S3 Bucket



RefControlSeverityVerification
TG-02All buckets must have a ManagedBy Tag of either terraform or ACME-CodeBuild unless the application is explicitly tagged as a "sandbox" Application with an Environment Tag of "Development"CriticalCheck bucket tags in discovery view


Current S3 Tags for ACME Payments Platform

How to verify: each bucket row auto-expands to show its tags — confirm every bucket carries a ManagedBy tag of terraform or ACME-CodeBuild (sandbox/development buckets are exempt).


If you believe the application "ACME Payment Platform" (ACME-INV: 0076193) is in compliance with this control you may record this below. If you believe it is not, or you don't have enough information, you should follow the process at the start of this document based on the control severity.



The application "ACME Payment Platform" is in Compliance with Data Protection Control TG-02

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All S3 buckets have a ManagedBy tag value present
  • If the application has an Application tag set to sandbox and an Environment Tag set to development it is excluded from this control.
  • All other S3 Buckets have a ManagedBy tag set to either terraform or ACME-Codebuild


Data Classification Tags Must be set for Every S3 Bucket



RefControlSeverityVerification
TG-01All buckets must have a data-classification tag with one of the following values: public, internal, confidential, or highly-confidential.CriticalCheck bucket tags in discovery view


Current S3 Tags for ACME Payments Platform

How to verify: confirm every bucket's tags include a data-classification value of public, internal, confidential, or highly-confidential. A bucket with no such tag is a control break.


If you believe the application "ACME Payment Platform (ACME-INV: 0076193)" is in compliance with this control you may record this below. If you believe it is not, or you don't have enough information, you should follow the process at the start of this document based on the control severity.


The application "ACME Payment Platform" is in Compliance with Data Protection Control TG-01

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All S3 Buckets have a data-classification tag with one of the following values: public , internal , confidential , or highly-confidential


Public Access to S3 Must Be Disabled



RefControlSeverityVerification
AC-01No S3 bucket shall have public access enabled. The S3 Block Public Access settings must be enabled at both the account level and the individual bucket level.CriticalCheck bucket policy and Block Public Access settings


Current S3 Public Access Configuration for ACME Payments Platform


If you believe the application "ACME Payment Platform (ACME-INV: 0076193)" is in compliance with this control you may record this below. If you believe it is not, or you don't have enough information, you should follow the process at the start of this document based on the control severity.


The application "ACME Payment Platform" is in Compliance with Data Protection Control AC-01

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All public access to all S3 buckets in scope for this application is blocked.


CloudTrail Logging Must be Enabled for All S3 Buckets



RefControlSeverityVerification
LG-02CloudTrail data events for S3 must be enabled for all buckets containing restricted or highly-restricted data.HighCheck CloudTrail configuration

Current CloudTrail Logs Configuration for ACME Payments Platform

How to verify: the trail must be Multi-region = yes with Log-file validation = yes, and Has custom event selectors = yes (the S3 data-event selectors that capture object-level access).


If you believe the application "ACME Payment Platform (ACME-INV: 0076193) is in compliance with this control you may record this below. If you believe it is not, or you don't have enough information, you should follow the process at the start of this document based on the control severity.



The application "ACME Payment Platform" is in Compliance with Data Protection Control LG-02

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All CloudTrail Data Events are enabled for buckets containing Restricted or Highly Restricted Data


No Bucket May Share Data With an Unregistered External Account



RefControlSeverityVerification
AC-02No S3 bucket policy shall grant access to an external AWS account or principal outside the ACME Approved Data-Sharing Register (ACME-DSR-001). All cross-account access must be reviewed and time-bound.HighIAM Access Analyzer — external-access findings


Cross-account & external access findings for ACME Payment Platform


Every finding must be either a registered sharing arrangement (ACME-DSR-001) or removed. If you believe the application "ACME Payment Platform" is in compliance with this control you may record this below.


The application "ACME Payment Platform" is in Compliance with Access Control AC-02

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • Every external principal with access to an in-scope bucket is listed in the Approved Data-Sharing Register (ACME-DSR-001)


All Buckets Must Use SSE-KMS With a Customer-Managed Key



RefControlSeverityVerification
EN-01All S3 buckets must enforce default encryption using SSE-KMS with an ACME customer-managed key (CMK). Buckets encrypted with SSE-S3 (AES-256), or unencrypted, are non-compliant.CriticalCheck default encryption in discovery view


Current S3 default encryption for ACME Payment Platform

How to verify: the Default encryption column must read aws:kms for every bucket. AES256 (SSE-S3) or None is a control break.


Any bucket showing AES-256 or None is a control break. If you believe the application "ACME Payment Platform" is in compliance with this control you may record this below.


The application "ACME Payment Platform" is in Compliance with Encryption Control EN-01

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All in-scope buckets enforce default encryption with an ACME customer-managed KMS key (aws:kms), not AES-256 or unencrypted


KMS Keys Encrypting S3 Data Must Have Rotation Enabled



RefControlSeverityVerification
EN-02All customer-managed KMS keys used to encrypt S3 data must have automatic annual key rotation enabled.HighKMS key rotation status


KMS key & secret rotation for ACME Payment Platform


If you believe the application "ACME Payment Platform" is in compliance with this control you may record this below.


The application "ACME Payment Platform" is in Compliance with Encryption Control EN-02

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • Every customer-managed key used for in-scope S3 data has automatic rotation enabled


Bucket Policies Must Enforce TLS-Only Access



RefControlSeverityVerification
AC-03All S3 bucket policies must deny non-TLS requests by enforcing the aws:SecureTransport condition (TLS-only access).HighCheck bucket policy for aws:SecureTransport


Current S3 TLS-only policy status for ACME Payment Platform

How to verify: for each bucket, click View policy and confirm a Deny statement on the condition aws:SecureTransport = false (rejects non-TLS access).


If you believe the application "ACME Payment Platform" is in compliance with this control you may record this below.


The application "ACME Payment Platform" is in Compliance with Access Control AC-03

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • Every in-scope bucket policy denies requests where aws:SecureTransport is false


Confidential Buckets Must Have Versioning Enabled



RefControlSeverityVerification
RS-01All buckets containing confidential or highly-confidential data must have S3 Versioning enabled to protect against accidental or malicious deletion and to support ransomware recovery.MediumCheck bucket versioning status


Current S3 versioning status for ACME Payment Platform

How to verify: each row auto-expands to show its tags — for every bucket tagged data-classification = confidential or highly-confidential, the Versioning column must read Enabled. Disabled or Suspended on such a bucket is a control break.


If you believe the application "ACME Payment Platform" is in compliance with this control you may record this below.


The application "ACME Payment Platform" is in Compliance with Resilience Control RS-01

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • Every confidential or highly-confidential bucket has versioning enabled

End of Review

Thank you, you have now reached the end of the annual S3 Security Controls Review for the Application: ACME Payment Platform (ACME-INV: 0076193).

If you were unable to attest to compliance with any of the above controls you must follow the process at the start of this document and either raise a remediation plan or raise a critical incident in the event of non compliance with a critical control. There are no consequences for raising a control break at this stage as long as the correct processes are followed to report and remediate in the appropriate time.

If you have confirmed the applications compliance with all the controls in the scope of this review please check the final checkpoint below. Please note that submitting incorrect information or failing to raise concerns around controls breaks may carry consequences up to and including dismissal. If in doubt raise a Service Now request with the compliance team or Cloud Infosec.



The application "ACME Payment Platform" is in Compliance with the S3 Data Security Controls (ACME-DSC-S3-001)

Before proceeding, confirm the following:

  • I have enough information to attest to compliance, either from this portal or with additional research
  • All my answers are correct based on the information I have been presented with or through additional research.
  • I understand my responsibilities in providing accurate information and the processes for reporting any gaps in control implementation


Once you have selected every checkpoint an immutable copy of this document and your application's S3 and CloudTrails configuration at this point in time will be saved to an immutable object store and digitally signed to prevent modification. It will be reviewed and may be requested by external auditors or regulators as evidence for controls implementation.