Medium
S3
Regional
S3 general purpose buckets should log object-level write events
CIS v5.0.0CIS v3.0.0PCI DSS v4.0.1PCI DSS v10.2.1
Description
This control checks whether an AWS account has at least one AWS CloudTrail multi-Region trail configured to log all write data events for Amazon S3 buckets. The control fails if such a multi-Region trail is not present.
Remediation
Configure a CloudTrail multi-region trail to log S3 write data events.
Steps
- Open the AWS CloudTrail console.
- Select or create a multi-region trail.
- Edit the trail and go to 'Advanced settings' or 'Data events'.
- Add a data event selector for 'S3' service with 'All S3 buckets'.
- Set 'Event type' to 'Write only' or 'All'.
- Save the configuration.
Compliance
CIS v5.0.0CIS v3.0.0PCI DSS v4.0.1PCI DSS v10.2.1