Medium EKS Regional

EKS clusters should have audit logging enabled

NIST 800-53PCI DSS v4.0.1PCI DSS v10.2.1HIPAA

Description

Ensures EKS clusters have audit logging enabled to record API server activity.


Remediation

To enable audit logging for your EKS cluster, you need to configure the logging settings.

Steps

  1. Navigate to the Amazon EKS console
  2. Select your cluster
  3. Go to the 'Logging' tab
  4. Click 'Edit' to modify logging configuration
  5. Enable 'Audit' log type
  6. Save the configuration to enable audit logging
  7. Verify that audit logs are being sent to CloudWatch Logs

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v10.2.1HIPAA