Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

Log Group Encryption at Rest Enabled Rule

Ensure log group encryption at rest is enabled to maintain high security standards.

RuleLog group encryption at rest should be enabled
FrameworkNIST Cybersecurity Framework (CSF) v1.1
Severity
High

Rule Description:

The rule "Log group encryption at rest should be enabled for NIST Cybersecurity Framework (CSF) v1" ensures that encryption is enabled for log groups in order to adhere to the security requirements set by the NIST Cybersecurity Framework (CSF) version 1.

Troubleshooting Steps:

  1. 1.

    Verify Log Group Encryption Setting:

    • Check if encryption at rest is already enabled for the log groups.
    • Navigate to the AWS Management Console and open the CloudWatch service.
    • Go to the "Log groups" section and search for the relevant log group.
    • Click on the log group and look for the "Encryption" setting.
  2. 2.

    Enable Encryption at Rest:

    • If encryption at rest is not already enabled, you will need to enable it.
    • Select the log group that needs encryption enabled.
    • Click on the "Actions" dropdown menu, then select "Modify log group".
    • Under "Encryption (optional)", choose the encryption option that aligns with NIST CSF v1 requirements.
    • Save the changes.

Necessary Codes:

There are no specific codes required for this rule. Encryption settings can be modified directly through the AWS Management Console.

Remediation Steps:

To enable encryption at rest for log groups in AWS CloudWatch, follow these steps:

  1. 1.

    Open the AWS Management Console and navigate to the CloudWatch service.

  2. 2.

    From the CloudWatch dashboard, click on "Log groups" in the left sidebar.

  3. 3.

    Search for the relevant log group that needs encryption enabled, and click on it.

  4. 4.

    On the log group details page, click on the "Actions" dropdown menu above the log events.

  5. 5.

    Select "Modify log group" from the available options.

  6. 6.

    In the "Modify log group" dialog box, scroll down to the "Encryption (optional)" section.

  7. 7.

    Choose the encryption option that aligns with the NIST CSF v1 requirements. This can be done by selecting an appropriate KMS key or using the default CMK.

  8. 8.

    Once you have selected the encryption option, click on the "Save" button to apply the changes.

  9. 9.

    Verify that the encryption at rest is now enabled for the log group by checking the "Encryption" setting on the log group details page.

By following these steps, you can ensure that encryption at rest is enabled for log groups in accordance with the NIST CSF v1 requirements.

Is your System Free of Underlying Vulnerabilities?
Find Out Now