Skip to main content

💼 [CloudTrail.4] CloudTrail log file validation should be enabled

  • ID: /frameworks/aws-fsbp-v1.0.0/cloudtrail/04

Description

CloudTrail log file validation creates a digitally signed digest file that contains a hash of each log that CloudTrail writes to Amazon S3. You can use these digest files to determine whether a log file was changed, deleted, or unchanged after CloudTrail delivered the log.

Similar

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST SP 800-53 Revision 5 → 💼 AU-9 Protection of Audit Information725no data
💼 NIST SP 800-53 Revision 5 → 💼 SI-4 System Monitoring25110no data
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(1) Software, Firmware, and Information Integrity _ Integrity Checks1no data
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(3) Software, Firmware, and Information Integrity _ Centrally Managed Integrity Tools1no data
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(7) Software, Firmware, and Information Integrity _ Integration of Detection and Response1no data
💼 PCI DSS v3.2.1 → 💼 10.5.2 Protect audit trail files from unauthorized modifications.14no data
💼 PCI DSS v3.2.1 → 💼 10.5.5 Use file-integrity monitoring or change-detection software on logs to ensure that existing log data cannot be changed without generating alerts.12no data
💼 PCI DSS v4.0.1 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.4no data
💼 PCI DSS v4.0 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.24no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ AWS CloudTrail Log File Validation is not enabled🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-b1e1a4941