Skip to main content

πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)

  • Contextual name: πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)
  • ID: /frameworks/cis-aws-v4.0.1/03/02
  • Located in: πŸ’Ό 3 Logging

Description​

CloudTrail log file validation creates a digitally signed digest file containing a hash of each log that CloudTrail writes to S3. These digest files can be used to determine whether a log file was changed, deleted, or remained unchanged after CloudTrail delivered the log. It is recommended that file validation be enabled for all CloudTrails.

Similar​

  • Sections
    • /frameworks/cis-aws-v5.0.0/03/02
    • /frameworks/cis-aws-v4.0.0/03/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v4.0.0 β†’ πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)1
πŸ’Ό CIS AWS v5.0.0 β†’ πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v4.0.0 β†’ πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)1
πŸ’Ό CIS AWS v5.0.0 β†’ πŸ’Ό 3.2 Ensure CloudTrail log file validation is enabled (Automated)1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS CloudTrail Log File Validation is not enabled 🟒1🟒 x6