Skip to main content

💼 10.5.2 Protect audit trail files from unauthorized modifications.

Description

Empty...

Similar

  • Sections
    • /frameworks/pci-dss-v4.0/10/03/02
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/02
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/04
    • /frameworks/aws-fsbp-v1.0.0/config/01
  • Internal
    • ID: dec-c-e31ad590

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [CloudTrail.2] CloudTrail should have encryption at-rest enabled1
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [CloudTrail.4] CloudTrail log file validation should be enabled11
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Config.1] AWS Config should be enabled and use the service-linked role for resource recording1
💼 PCI DSS v4.0 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.24

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v4.0 → 💼 10.3.2 Audit log files are protected to prevent modifications by individuals.24

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (4)

PolicyLogic CountFlags
📝 AWS Account Config is not enabled in all regions 🟢1🟢 x6
📝 AWS Account IAM Access Analyzer is not enabled for all regions 🟢1🟢 x6
📝 AWS CloudTrail is not encrypted with KMS CMK 🟢1🟢 x6
📝 AWS CloudTrail Log File Validation is not enabled 🟢1🟢 x6

Internal Rules

RulePoliciesFlags
✉️ dec-x-b1e1a4941