Skip to main content

💼 [CloudTrail.4] CloudTrail log file validation should be enabled

  • Contextual name: 💼 [CloudTrail.4] CloudTrail log file validation should be enabled
  • ID: /frameworks/aws-fsbp-v1.0.0/cloudtrail/04
  • Located in: 💼 CloudTrail

Description

CloudTrail log file validation creates a digitally signed digest file that contains a hash of each log that CloudTrail writes to Amazon S3. You can use these digest files to determine whether a log file was changed, deleted, or unchanged after CloudTrail delivered the log.

Similar

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST SP 800-53 Revision 5 → 💼 AU-9 Protection of Audit Information724
💼 NIST SP 800-53 Revision 5 → 💼 SI-4 System Monitoring2518
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(1) Software, Firmware, and Information Integrity _ Integrity Checks1
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(3) Software, Firmware, and Information Integrity _ Centrally Managed Integrity Tools1
💼 NIST SP 800-53 Revision 5 → 💼 SI-7(7) Software, Firmware, and Information Integrity _ Integration of Detection and Response1
💼 PCI DSS v3.2.1 → 💼 10.5.2 Protect audit trail files from unauthorized modifications.14
💼 PCI DSS v3.2.1 → 💼 10.5.5 Use file-integrity monitoring or change-detection software on logs to ensure that existing log data cannot be changed without generating alerts.12
💼 PCI DSS v4.0.1 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.4
💼 PCI DSS v4.0 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.24

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 AWS CloudTrail Log File Validation is not enabled 🟢1🟢 x6

Internal Rules

RulePoliciesFlags
✉️ dec-x-b1e1a4941