Medium
Identify
Regional
ActiveMQ brokers should stream audit logs to CloudWatch
NIST 800-53PCI DSS v4.0.1PCI DSS v10.3.3ISO 27001HIPAA
Description
Verifies that Amazon MQ ActiveMQ brokers stream audit logs to CloudWatch Logs, enabling alarm creation and increased visibility into security-related activity.
Remediation
To remediate ActiveMQ brokers without audit logs streaming to CloudWatch, you need to enable audit logging for the broker.
Steps
- Navigate to the Amazon MQ console
- Select the ActiveMQ broker that needs remediation
- Click on 'Edit' or 'Modify' broker
- Go to 'Logs' settings
- Enable 'Audit' logging
- Configure CloudWatch Logs destination
- Set up log groups and retention policies
- Review the logging configuration
- Apply the changes to the broker
- Verify audit logs are streaming to CloudWatch
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v10.3.3ISO 27001HIPAA