Medium
CloudTrail
Regional
CloudTrail Lake event data stores should be encrypted with customer managed AWS KMS keys
NIST 800-53
Description
Confirms that CloudTrail Lake event data stores are encrypted at rest with a customer managed KMS key.
Remediation
Configure your CloudTrail Lake event data store to use a customer managed KMS key for encryption instead of the default S3 managed keys.
Steps
- Navigate to the CloudTrail console
- Go to the CloudTrail Lake section
- Select the event data store that needs KMS encryption
- Edit the event data store configuration
- In the encryption settings, select 'Customer managed key'
- Choose or create a customer managed KMS key
- Save the configuration changes
- Verify that the event data store is now encrypted with the customer managed KMS key
Compliance
NIST 800-53