Security
When you build systems on AWS infrastructure, security
responsibilities are shared between you and AWS. This
shared
responsibility model
Amazon S3 bucket policy
The S3 buckets for MediaConvert output include a policy that allows access from CloudFront. Because the CloudFront endpoints are publicly accessible, the MediaConvert output bucket is also publicly accessible when accessed with CloudFront. For information on how to secure Amazon CloudFront, refer to Serving private content with signed URLs and signed cookies in the Amazon CloudFront Developer Guide.
IAM roles
IAM roles allow you to assign granular access policies and permissions to services and users on the AWS Cloud. This solution creates several IAM roles, including a role that grants MediaConvert access to Amazon S3. This role is necessary to allow the services to operate in your account.