AWS Security ChangesHomeSearch

AWS controltower high security documentation change

Service: controltower · 2026-02-19 · Security-related high

File: controltower/latest/controlreference/control-parameter-concepts.md

Summary

Updated control descriptions to focus on preventing modifications of S3 bucket encryption, logging, and policies

Security assessment

The changes strengthen documentation about security controls that prohibit modification of security configurations (encryption settings, access logging, and bucket policies). Preventing unauthorized changes to these configurations is a security enforcement measure to maintain audit integrity and data protection.

Diff

diff --git a/controltower/latest/controlreference/control-parameter-concepts.md b/controltower/latest/controlreference/control-parameter-concepts.md
index db4926c92..19dc8e4ee 100644
--- a//controltower/latest/controlreference/control-parameter-concepts.md
+++ b//controltower/latest/controlreference/control-parameter-concepts.md
@@ -53,3 +53,3 @@ For more details about configuring controls with parameters, see [`ControlParame
-AWS-GR_AUDIT_BUCKET_ENCRYPTION_ENABLED | Enable encryption at rest for log archive  
-AWS-GR_AUDIT_BUCKET_LOGGING_ENABLED | Enable access logging for log archive  
-AWS-GR_AUDIT_BUCKET_POLICY_CHANGES_PROHIBITED | Disallow policy changes to log archive  
+AWS-GR_AUDIT_BUCKET_ENCRYPTION_ENABLED | Disallow modification of an Amazon S3 bucket default encryption  
+AWS-GR_AUDIT_BUCKET_LOGGING_ENABLED | Disallow modification of server access logging for an Amazon S3 bucket  
+AWS-GR_AUDIT_BUCKET_POLICY_CHANGES_PROHIBITED | Disallow policy changes to an Amazon S3 bucket