Medium CloudTrail Regional

CloudTrail Lake event data stores should be encrypted with customer managed AWS KMS keys

NIST 800-53

Description

Confirms that CloudTrail Lake event data stores are encrypted at rest with a customer managed KMS key.


Remediation

Configure your CloudTrail Lake event data store to use a customer managed KMS key for encryption instead of the default S3 managed keys.

Steps

  1. Navigate to the CloudTrail console
  2. Go to the CloudTrail Lake section
  3. Select the event data store that needs KMS encryption
  4. Edit the event data store configuration
  5. In the encryption settings, select 'Customer managed key'
  6. Choose or create a customer managed KMS key
  7. Save the configuration changes
  8. Verify that the event data store is now encrypted with the customer managed KMS key

Compliance

NIST 800-53