More Info:

Your trails should have file integrity validation feature enabled in order to check the log files and detect whether these were modified or deleted after CloudTrail agent delivered them to the S3 bucket.

Risk Level

Medium

Address

Security

Compliance Standards

HIPAA, CISAWS, CBP, SOC2, NIST, GDPR

Triage and Remediation

Remediation

To remediate the misconfiguration “File Integrity Validation Feature Should Be Enabled For Trails” for AWS using AWS console, follow these steps:

  1. Login to the AWS Management Console.
  2. Go to the CloudTrail service.
  3. Select the trail for which you want to enable file integrity validation.
  4. Click on the “Edit” button in the “Trail details” section.
  5. In the “Advanced” section, enable the “Enable log file integrity validation” option.
  6. Click on the “Save” button to save the changes.

Once you have enabled file integrity validation for the CloudTrail trail, it will start validating the integrity of log files to ensure that they have not been tampered with. This will help you maintain the integrity and security of your CloudTrail logs.

Additional Reading: