Mods
AWS

Control: AWS > PCI v3.2.1 > CloudTrail > 3 CloudTrail log file validation should be enabled

This control checks whether CloudTrail log file validation is enabled.

It does not check when configurations are altered.

To monitor and alert on log file changes, you can use Amazon EventBridge or CloudWatch metric filters.

Remediation

To enable CloudTrail log file validation

  1. Open the CloudTrail console at CloudTrail.
  2. In the navigation pane, choose Trails.
  3. In the Name column, choose the Trail Name to edit.
  4. Under General details, choose Edit.
  5. Under Additional settings, for Log file validation,, select Enabled.
  6. Choose Save.

PCI requirement(s): 10.5.2, 10.5.5

Resource Types

This control targets the following resource types:

Category

In Your Workspace

Developers