More Info:

CloudTrail should be enabled for all AWS regions in order to increase the visibility of the API activity in your AWS account for security and management purposes.

Risk Level

High

Address

Reliability, Security

Compliance Standards

HIPAA, PCIDSS, GDPR, CISAWS, CBP, NIST, SOC2, ISO27001, AWSWAF, NISTCSF, FedRAMP

Triage and Remediation

Remediation

To remediate the misconfiguration “CloudTrail Must Be Enabled For All Regions” for AWS, you can follow the below steps:

  1. Log in to your AWS Management Console.
  2. Go to the AWS CloudTrail service homepage.
  3. Click on the “Trails” option from the left-hand menu.
  4. Select the trail that you want to modify from the list of trails.
  5. Click on the “Edit” button.
  6. In the “Management events” section, select “All” from the “Apply trail to all regions” dropdown.
  7. Click on the “Save” button to save the changes.

This configuration change will enable CloudTrail for all regions in your AWS account.

Additional Reading: