πΌ [CodeBuild.3] CodeBuild S3 logs should be encrypted
- Contextual name: πΌ [CodeBuild.3] CodeBuild S3 logs should be encrypted
- ID:
/frameworks/aws-fsbp-v1.0.0/codebuild/03
- Located in: πΌ CodeBuild
Descriptionβ
Encryption of data at rest is a recommended best practice to add a layer of access management around your data. Encrypting the logs at rest reduces the risk that a user not authenticated by AWS will access the data stored on disk. It adds another set of access controls to limit the ability of unauthorized users to access the data.
Similarβ
- AWS Security Hub
- Internal
- ID:
dec-c-132e6374
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST SP 800-53 Revision 5 β πΌ CA-9(1) Internal System Connections _ Compliance Checks | 20 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ CM-3(6) Configuration Change Control _ Cryptography Management | 6 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-13 Cryptographic Protection | 4 | 13 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-28 Protection of Information at Rest | 3 | 16 | 25 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SC-28(1) Protection of Information at Rest _ Cryptographic Protection | 10 | 14 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SI-7(6) Software, Firmware, and Information Integrity _ Cryptographic Protection | 12 | |||
πΌ PCI DSS v4.0 β πΌ 10.3.2 Audit log files are protected to prevent modifications by individuals. | 2 | 4 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|