πΌ [CloudTrail.5] CloudTrail trails should be integrated with Amazon CloudWatch Logs
-
Contextual name: πΌ [CloudTrail.5] CloudTrail trails should be integrated with Amazon CloudWatch Logs
-
ID: /frameworks/aws-fsbp-v1.0.0/cloudtrail/05
-
Located in: πΌ CloudTrail
Descriptionβ
CloudTrail records AWS API calls that are made in a given account. The recorded
information includes the following:
- The identity of the API caller
- The time of the API call
- The source IP address of the API caller
- The request parameters
- The response elements returned by the AWS service
CloudTrail uses Amazon S3 for log file storage and delivery. You can capture
CloudTrail logs in a specified S3 bucket for long-term analysis. To perform real-time
analysis, you can configure CloudTrail to send logs to CloudWatch Logs.
For a trail that is enabled in all Regions in an account, CloudTrail sends log
files from all of those Regions to a CloudWatch Logs log group.
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
πΌ NIST SP 800-53 Revision 5 β πΌ AC-2(4) Account Management _ Automated Audit Actions | | 11 | 13 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AC-4(26) Information Flow Enforcement _ Audit Filtering Actions | | | 7 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AC-6(9) Least Privilege _ Log Use of Privileged Functions | | 15 | 16 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-2 Event Logging | 4 | | 6 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-3 Content of Audit Records | 3 | 13 | 20 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-6(1) Audit Record Review, Analysis, and Reporting _ Automated Process Integration | | 1 | 1 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-6(3) Audit Record Review, Analysis, and Reporting _ Correlate Audit Record Repositories | | | 6 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-6(4) Audit Record Review, Analysis, and Reporting _ Central Review and Analysis | | | 6 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-6(5) Audit Record Review, Analysis, and Reporting _ Integrated Analysis of Audit Records | | | | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-7(1) Audit Record Reduction and Report Generation _ Automatic Processing | | 1 | 1 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-10 Non-repudiation | 5 | | 5 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AU-12 Audit Record Generation | 4 | 45 | 47 | |
πΌ NIST SP 800-53 Revision 5 β πΌ CA-7 Continuous Monitoring | 6 | | 8 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(9) Boundary Protection _ Restrict Threatening Outgoing Communications Traffic | | | 7 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SI-3(8) Malicious Code Protection _ Detect Unauthorized Commands | | | 3 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SI-4(5) System Monitoring _ System-generated Alerts | | | | |
πΌ NIST SP 800-53 Revision 5 β πΌ SI-4(20) System Monitoring _ Privileged Users | | | 3 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SI-7(8) Software, Firmware, and Information Integrity _ Auditing Capability for Significant Events | | | 6 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SI-20 Tainting | | | | |
πΌ PCI DSS v3.2.1 β πΌ 10.5.3 Promptly back up audit trail files to a centralized log server or media that is difficult to alter. | | | | |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|