CIS Control 3

3.2 Ensure CloudTrail Log File Validation is Enabled (Automated)
Profile Applicability: Level 2 Description: AWS CloudTrail Log File Validation provides a cryptographic hash for every log file stored in S3. It helps de...
Mon, 17 Feb, 2025 at 11:54 PM
3.3 Ensure AWS Config is Enabled in All Regions (Automated)
Profile Applicability: Level 2 Description: AWS Config is a managed service that continuously monitors and records AWS resource configurations. It tracks...
Tue, 18 Feb, 2025 at 2:35 AM
3.4 Ensure Server Access Logging is Enabled on the CloudTrail S3 Bucket (Automated)
Profile Applicability: Level 1 Description: AWS Server Access Logging for CloudTrail S3 buckets provides detailed records of requests made to an S3 bucke...
Tue, 18 Feb, 2025 at 2:55 AM
3.5 Ensure CloudTrail Logs Are Encrypted at Rest Using KMS CMKs (Automated)
Profile Applicability: Level 2 Description AWS CloudTrail records AWS API calls and logs them to an S3 bucket. Encrypting CloudTrail logs with AWS Key Ma...
Wed, 19 Feb, 2025 at 6:07 AM
3.6 Ensure Rotation for Customer-Created Symmetric CMKs Is Enabled (Automated)
Profile Applicability: Level 2 Description: AWS Key Management Service (KMS) allows customers to automate key rotation for customer-managed keys (CMKs). ...
Wed, 19 Feb, 2025 at 6:47 AM
3.8 Ensure that object-level logging for write events is enabled for S3 buckets
Profile Applicability: Level 2 Description: AWS S3 Object-Level API Operations (PutObject, DeleteObject, GetObject) are categorized as Data Events in AWS...
Wed, 19 Feb, 2025 at 7:00 AM
3.7 Ensure VPC flow logging is enabled in all VPCs
Profile Applicability: Level 2 Description: AWS VPC Flow Logs capture IP traffic flowing to and from network interfaces in a VPC. These logs help in secu...
Wed, 19 Feb, 2025 at 7:11 AM
3.9 Ensure Object-Level Logging for Read Events Is Enabled for S3 Buckets (Automated)
Profile Applicability: Level 2 Description: AWS S3 Object-Level API Operations (GetObject, DeleteObject, PutObject) are categorized as Data Events in AWS...
Wed, 19 Feb, 2025 at 7:22 AM