Medium S3

S3 general purpose buckets should log object-level write events

CIS v5.0.0CIS v3.0.0PCI DSS v4.0.1PCI DSS v10.2.1

Description

Confirms that at least one CloudTrail multi-Region trail is configured to log all S3 object write events.


Remediation

Configure a CloudTrail multi-region trail to log S3 write data events.

Steps

  1. Open the AWS CloudTrail console.
  2. Select or create a multi-region trail.
  3. Edit the trail and go to 'Advanced settings' or 'Data events'.
  4. Add a data event selector for 'S3' service with 'All S3 buckets'.
  5. Set 'Event type' to 'Write only' or 'All'.
  6. Save the configuration.

Compliance

CIS v5.0.0CIS v3.0.0PCI DSS v4.0.1PCI DSS v10.2.1