Medium
DocumentDB
Regional
Amazon DocumentDB clusters should publish audit logs to CloudWatch Logs
NIST 800-53PCI DSS v4.0.1PCI DSS v10.3.3ISO 27001HIPAA
Description
Verifies that DocumentDB clusters publish audit logs to CloudWatch Logs. Audit logging captures authentication attempts, collection drops, index creation, and other significant events.
Remediation
Enable audit logging for your Amazon DocumentDB cluster by configuring CloudWatch Logs export for audit logs.
Steps
- Open the Amazon DocumentDB console.
- Choose 'Clusters' from the navigation pane.
- Select the cluster you want to modify.
- Choose 'Modify'.
- In the 'Log exports' section, select 'audit' to enable audit logs.
- Choose 'Continue' and then 'Modify cluster'.
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v10.3.3ISO 27001HIPAA