Mods
AWS

Policy: AWS > CIS v2.0 > 3 - Logging > 3.09 - Ensure VPC flow logging is enabled in all VPCs

Configures auditing against a CIS Benchmark item.

Level: 2

VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. After you've created a flow log, you can view and retrieve its data in Amazon CloudWatch Logs. It is recommended that VPC Flow Logs be enabled for packet "Rejects" for VPCs.

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Policy Specification

Schema Type
string
Default
Per AWS > CIS v2.0 > 3 - Logging
Valid Values [YAML]
  • Per AWS > CIS v2.0 > 3 - Logging
    
  • Skip
    
  • Check: Benchmark
    

Category

In Your Workspace

Developers