Skip to content

AWS logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On AWS, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the AWS connector needs.

Checks (6)

severity: critical CloudTrail Not Logging fix difficulty: easy #

Enable logging on the CloudTrail trail to ensure API activity is being recorded

  1. Navigate to CloudTrail > Trails in the AWS Console
  2. Click the trail name to open it
  3. If logging is stopped, click "Start logging" in the trail details
  4. If no trail exists, click "Create trail" and configure it with an S3 bucket destination
  5. Enable log file validation and optionally send logs to CloudWatch Logs
  6. Verify the trail status shows "Logging" as active

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: medium CloudTrail Log Validation Disabled fix difficulty: easy #

Enable log file validation on the CloudTrail trail to detect tampering

  1. Navigate to CloudTrail > Trails in the AWS Console
  2. Click the trail name to open it
  3. Click "Edit" in the trail configuration section
  4. Under "Additional settings", enable "Log file validation"
  5. Click "Save changes"
  6. Verify the trail detail page shows "Log file validation enabled"

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high CloudTrail Not Multi-Region fix difficulty: easy #

Configure the CloudTrail trail to log events across all AWS regions

  1. Navigate to CloudTrail > Trails in the AWS Console
  2. Click the trail name to open it
  3. Click "Edit" in the trail configuration section
  4. Under "Trail settings", set "Apply trail to all regions" to enabled
  5. Click "Save changes"
  6. Verify the trail is now listed as a multi-region trail

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high CloudTrail Data Events Disabled fix difficulty: medium #

Enable data event logging for S3, Lambda, and DynamoDB on the CloudTrail trail

  1. Navigate to CloudTrail > Trails in the AWS Console
  2. Click the trail name to open it
  3. Click "Edit" on the "Data events" section
  4. Enable data events for the services you need (S3, Lambda, DynamoDB)
  5. Scope the selectors to specific buckets or functions to control cost
  6. Click "Save changes"

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high VPC Flow Logs Disabled fix difficulty: easy #

Enable VPC flow logs to capture accepted and rejected traffic metadata

  1. Navigate to VPC > Your VPCs in the AWS Console
  2. Select the flagged VPC
  3. Under the "Flow logs" tab, click "Create flow log"
  4. Set filter to "All", choose "CloudWatch Logs" or "S3" as the destination
  5. Provide an IAM role with permission to write flow logs
  6. Click "Create flow log" and verify it appears as "Active"

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high AWS Config Not Recording fix difficulty: medium #

Enable AWS Config in every active region and record all supported resource types

  1. Navigate to AWS Config in the flagged region
  2. Click "Get started" if Config has never been enabled
  3. Under "Recording strategy", choose "Record all resources supported in this region"
  4. Include global resources in at least one region
  5. Provide an S3 bucket and optional SNS topic for the delivery channel
  6. Click "Confirm" and verify the recorder shows "Recording is on"

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

More AWS checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial