Skip to main content

💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)

  • Contextual name: 💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)
  • ID: /frameworks/cis-aws-v4.0.1/03/08
  • Located in: 💼 3 Logging

Description

S3 object-level API operations, such as GetObject, DeleteObject, and PutObject, are referred to as data events. By default, CloudTrail trails do not log data events, so it is recommended to enable object-level logging for S3 buckets.

Similar

  • Sections
    • /frameworks/cis-aws-v5.0.0/03/08
    • /frameworks/cis-aws-v4.0.0/03/08

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v4.0.0 → 💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1
💼 CIS AWS v5.0.0 → 💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v4.0.0 → 💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1
💼 CIS AWS v5.0.0 → 💼 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 AWS Account Object-level CloudTrail Logging for Write Events for S3 Buckets is not enabled 🟢1🟢 x6