CLOUDTRAIL: CloudTrail logs are not publicly accessible - 'Review S3 Buckets

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

CloudTrail logs a record API calls made in your AWS account. Allowing public access to CloudTrail log content may aid an attackery in identifying weaknesses.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review S3 Buckets for public access.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CCE|CCE-78915-6, CSCv6|6

Plugin: amazon_aws

Control ID: 7670d1c2fc4d52d2087ea1647f8e93c130bc44498f30436646c53d45723d7b2e