Medium S3

S3 general purpose buckets should have server access logging enabled

NISTISO 27001HIPAA

Description

Verifies that S3 bucket server access logging is enabled.


Remediation

To enable server access logging for an S3 bucket, follow these steps:

Steps

  1. Sign in to the AWS Management Console and open the Amazon S3 console.
  2. In the Buckets list, choose the name of the bucket for which you want to enable server access logging.
  3. Choose the 'Properties' tab.
  4. In the 'Server access logging' section, choose 'Edit'.
  5. Select 'Enable' for server access logging.
  6. In the 'Target bucket' field, enter the name of the bucket where you want the log files to be stored.
  7. Optionally, you can specify a prefix for the log files in the 'Target prefix' field.
  8. Choose 'Save changes'.

Compliance

NISTISO 27001HIPAA