A trail in ActionTrail is considered compliant if it is enabled and tracks all regions and all event types.
Scenarios
Compliance standards such as Multi-Level Protection Scheme (MLPS) Level 3 pre-checks, CIS Network Security framework checks, and OSS compliance management require that all cloud operation logs be retained for at least 180 days. When you detect malicious attacks, malicious operations, or system failures, complete operation logs help you preserve evidence and quickly identify issues.
Risk level
Default risk level: High risk.
You can change the risk level as needed.
Detection logic
-
A trail is considered compliant if it is enabled in ActionTrail and configured to track all regions and all event types.
-
A trail is considered non-compliant if no trail is created in ActionTrail, an existing trail is disabled, or an enabled trail is configured to track only some regions or event types. To fix this issue, see Remediation.
Rule details
|
Parameter |
Description |
|
Rule name |
Enable full log trails in ActionTrail |
|
Rule identifier |
actiontrail-trail-intact-enabled |
|
Tag |
ActionTrail |
|
Automatic remediation |
Not supported |
|
Rule trigger mechanism |
Periodic |
|
Trigger frequency |
24 hours |
|
Rule input parameters |
None |
Remediation
Configure the trail to log all event types. For more information, see Update a single-account trail.