CLOUDTRAIL: CloudTrail logs are encrypted at rest

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

CloudTrail logs a record API calls made in your AWS account. It is recommended that CloudTrail be configured to use SSE-KMS.

Solution

Verify the key being used to encrypt your logs.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28, CCE|CCE-78919-8, CSCv6|6, CSCv6|13.1

Plugin: amazon_aws

Control ID: 4f92802a22f1b5b854bff39326194ad8aa67ddf912c20c7ab61bc9d098cb9cce