More Info:

Your Amazon CloudTrail trail should be configured to use the appropriated S3 bucket in order to meet regulatory compliance requirements within your organization

Risk Level

Medium

Address

Security

Compliance Standards

SOC2

Triage and Remediation

Remediation

To remediate the misconfiguration “CloudTrails Must Log Management Events” for AWS using the AWS console, follow these steps:

  1. Log in to the AWS Management Console and navigate to the CloudTrail service.

  2. Select the Trail that you want to modify and click on the “Edit” button.

  3. Scroll down to the “Management events” section and ensure that the “Read/Write events” checkbox is selected.

  4. Click on the “Save” button to save the changes.

  5. Repeat these steps for all the trails that you have configured in your AWS account.

By following these steps, you will ensure that CloudTrail logs all management events, including API calls made by users and services in your AWS account. This will help you to monitor and audit your AWS environment effectively and ensure compliance with your security policies.

Additional Reading: