💼 3.9 Ensure that object-level logging for read events is enabled for S3 buckets (Automated)
- Contextual name: 💼 3.9 Ensure that object-level logging for read events is enabled for S3 buckets (Automated)
- ID:
/frameworks/cis-aws-v4.0.1/03/09
- Located in: 💼 3 Logging
Description
S3 object-level API operations, such as GetObject, DeleteObject, and PutObject, are referred to as data events. By default, CloudTrail trails do not log data events, so it is recommended to enable object-level logging for S3 buckets.
Similar
- Sections
/frameworks/cis-aws-v5.0.0/03/09
/frameworks/cis-aws-v4.0.0/03/09
Similar Sections (Take Policies From)
Similar Sections (Give Policies To)
Sub Sections
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)