I got an AWS question and implemented it to make sure that the option is correct.

You have 30 AWS accounts under Organizations. A developer in one of them creates an S3 bucket, skips encryption, and now you have a compliance gap. By the time your next audit runs, there are three more buckets in the same state.

This post covers how to close that gap permanently: stopping unencrypted buckets before they are created, and fixing the ones that already exist.

Prerequisites

Check these before running terraform apply: