πΌ [CloudTrail.2] CloudTrail should have encryption at-rest enabled
- Contextual name: πΌ [CloudTrail.2] CloudTrail should have encryption at-rest enabled
- ID:
/frameworks/aws-fsbp-v1.0.0/cloudtrail/02
- Located in: πΌ CloudTrail
Descriptionβ
For an added layer of security for your sensitive CloudTrail log files, you should use
server-side encryption with AWS KMS keys (SSE-KMS) for your CloudTrail log files
for encryption at rest. Note that by default, the log files delivered by
CloudTrail to your buckets are encrypted by Amazon server-side encryption with
Amazon S3-managed encryption keys (SSE-S3).
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)β