AWS Foundational Security Best Practices standard

S3 controls

[S3.1] S3 general purpose buckets should have block public access settings enabled

[S3.5] S3 general purpose buckets should require requests to use SSL

IAM controls

[IAM.5] MFA should be enabled for all IAM users that have a console password

Other

[Account.1] Security contact information should be provided for an AWS account