💼 [CloudTrail.2] CloudTrail should have encryption at-rest enabled
- ID:
/frameworks/aws-fsbp-v1.0.0/cloudtrail/02
Stats
not available
Description
For an added layer of security for your sensitive CloudTrail log files, you should use server-side encryption with AWS KMS keys (SSE-KMS) for your CloudTrail log files for encryption at rest. Note that by default, the log files delivered by CloudTrail to your buckets are encrypted by Amazon server-side encryption with Amazon S3-managed encryption keys (SSE-S3).
Similar
- AWS Security Hub
- Internal
- ID:
dec-c-8b9dfb2b
- ID:
Similar Sections (Give Policies To)
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|
Policies (1)
| Policy | Logic Count | Flags | Compliance |
|---|---|---|---|
| 🛡️ AWS CloudTrail is not encrypted with KMS CMK🟢 | 1 | 🟢 x6 | no data |