More Info:
Your CloudTrail logs should be encrypted at rest using server-side encryption provided by AWS KMS–Managed Keys (SSE-KMS) to enhance the security of your CloudTrail bucketRisk Level
MediumAddress
SecurityCompliance Standards
- APRA CPS 234 (Australia)
- AWS Startup Security Baseline
- AWS Well Architected Framework
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS AWS
- CIS Critical Security Controls v8
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- Cloudanix Best Practice
- DPDPA
- Digital Operational Resilience Act (EU)
- GDPR
- HIPAA
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- PCI
- Reserve Bank of India (RBI) Cyber Security Framework
- SOC2
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- Securities and Exchange Board of India (SEBI) - Cloud Security Adoption Framework
- StateRAMP
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
To remediate the misconfiguration of unencrypted CloudTrail logs in AWS, follow these steps:
- Login to the AWS Management Console.
- Navigate to the CloudTrail service page.
- Select the trail that you want to modify, and click on “Edit” button.
- In the “Advanced” section, enable the “Enable log file encryption” option.
- Choose the AWS KMS key that you want to use for encryption.
- Click on “Save” button to save the changes.
Using CLI
Using CLI
To remediate the misconfiguration of unencrypted AWS CloudTrail logs using AWS CLI, follow the below steps:Replace Replace
- Open the AWS CLI on your local machine and run the following command to enable CloudTrail log encryption:
<trail_name> with the name of the CloudTrail trail that you want to encrypt, and <kms_key_id> with the ID of the KMS key that you want to use for encryption.- Verify that CloudTrail log encryption is enabled by running the following command:
<trail_name> with the name of the CloudTrail trail that you want to verify.- Check the AWS CloudTrail console to ensure that the CloudTrail logs are being encrypted.
Using Python
Using Python
To remediate the misconfiguration of unencrypted CloudTrail logs in AWS using Python, you can follow these steps:
- First, you need to check if CloudTrail logs are encrypted or not. For this, you can use the AWS SDK for Python (Boto3) and run the following code:
- If the CloudTrail logs are not encrypted, you need to create a KMS key and enable encryption for CloudTrail. You can use the following code to create a KMS key and enable encryption for CloudTrail:
- Once CloudTrail encryption is enabled, you can verify that the logs are encrypted by running the first code snippet again.
Using Terraform
Using Terraform
aws_cloudtrail to set kms_key_id is an in-place change and should not replace the trail, but it will cause new log files to be written encrypted with this KMS key; ensure no conflicting encryption settings exist on the S3 bucket policy.To verify, terraform plan should show:aws_kms_key.cloudtrail_logsbeing created, andaws_cloudtrail.thisupdated in-place withkms_key_idchanging fromnull(or a different key) to the ARN ofaws_kms_key.cloudtrail_logs.

