A joint design team must ensure that sensitive PII stored in S3 is never accidentally made public. Which preventive control enforces this at the organization level?
-
A
S3 bucket policies reviewed quarterly
-
B
AWS Organizations SCP blocking s3:PutBucketAcl with public grants, plus S3 Block Public Access enabled at the account level
-
C
IAM policies on each developer's role
-
D
CloudTrail logging all S3 API calls