More Info:

Cloudwatch loggroups should be encrypted

Risk Level

High

Address

Security

Compliance Standards

HIPAA,PCIDSS,GDPR,CISAWS,CBP,NIST,SOC2,AWSWAF,SEBI,RBI_UCB

Triage and Remediation

Remediation

Enabling encryption from console has some limitations, AWS does not allow KMS Key association with Log Groups from Console. Reference Link