Skip to main content

πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)

  • Contextual name: πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)
  • ID: /frameworks/cis-aws-v4.0.1/03/08
  • Located in: πŸ’Ό 3 Logging

Description​

S3 object-level API operations, such as GetObject, DeleteObject, and PutObject, are referred to as data events. By default, CloudTrail trails do not log data events, so it is recommended to enable object-level logging for S3 buckets.

Similar​

  • Sections
    • /frameworks/cis-aws-v5.0.0/03/08
    • /frameworks/cis-aws-v4.0.0/03/08

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v4.0.0 β†’ πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1
πŸ’Ό CIS AWS v5.0.0 β†’ πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v4.0.0 β†’ πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1
πŸ’Ό CIS AWS v5.0.0 β†’ πŸ’Ό 3.8 Ensure that object-level logging for write events is enabled for S3 buckets (Automated)1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS Account Object-level CloudTrail Logging for Write Events for S3 Buckets is not enabled 🟒1🟒 x6