Medium Transfer Regional

Transfer Family connectors should have logging enabled

NIST 800-53

Description

Verifies that CloudWatch logging is enabled for AWS Transfer Family connectors.


Remediation

To enable CloudWatch logging for Transfer Family connectors, configure a logging role for each connector.

Steps

  1. Open the AWS Transfer Family console.
  2. Select the connector that needs logging enabled.
  3. Go to the 'Logging' section in the connector settings.
  4. Create an IAM role with permissions to write logs to CloudWatch Logs.
  5. Attach the IAM role to the connector as the logging role.
  6. Save the connector configuration.

Compliance

NIST 800-53