The S3 bucket will remain private and public access will be blocked.
CloudFront Origin Access Control allows CloudFront to securely access the S3 bucket.
HTTPS will be configured using an SSL/TLS certificate from AWS Certificate Manager.
AWS WAF will inspect web requests and protect the CloudFront distribution.
IAM will be used to control access to AWS resources using least privilege.
CloudTrail will provide an audit trail of AWS API activity.