Control: AWS > NIST 800-53 > CloudTrail > CloudTrail trail logs should be encrypted with KMS CMK
To help protect sensitive data at rest, ensure encryption is enabled for your Amazon CloudWatch Log Groups.
Resource Types
This control targets the following resource types:
Category
In Your Workspace
Developers
- tmod:@turbot/aws-nist-800-53#/control/types/cloudTrailTrailLogsEncryptedWithKmsCmk
- tmod:@turbot/turbot#/control/categories/complianceNist80053
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-nist-800-53#/control/types/cloudTrailTrailLogsEncryptedWithKmsCmk"
Get Controls
Control Type URI
Category URI
GraphQL
CLI