Medium
CloudTrail
Regional
CloudTrail should have encryption at-rest enabled
PCI DSSCISNISTISO 27001
Description
Verifies that CloudTrail trails use server-side encryption with an AWS KMS key.
Remediation
Update a trail to use a KMS key.
Steps
- Sign in to the AWS Management Console and open the CloudTrail console.
- Choose Trails and select a trail name.
- In General details, choose Edit.
- Enable Log file SSE-KMS encryption and select or specify a KMS key.
- Update the trail.
Compliance
PCI DSSCISNISTISO 27001