DataBiosphere / azul

Metadata indexer and query service used for AnVIL, HCA, LungMAP, and CGP
Apache License 2.0
7 stars 2 forks source link

CloudFront distributions should have logging enabled #5271

Open hannes-ucsc opened 1 year ago

hannes-ucsc commented 1 year ago

@theathorn commented on Tue Feb 28 2023

@danielsotirhos commented on Fri Nov 04 2022

{
    "GeneratorIds": [
        "aws-foundational-security-best-practices/v/1.0.0/CloudFront.5"
    ]
}

https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-fsbp-controls.html#fsbp-cloudfront-5



@hannes-ucsc commented on Fri Feb 17 2023

There is no work for us since Azul doesn't use CF. Only the DB does. So we need a DB ticket and set that as a blocker of this one.


@MillenniumFalconMechanic commented on Fri May 19 2023

@bvizzier-ucsc, @hannes-ucsc, can this ticket be closed?

dsotirho-ucsc commented 1 year ago

Assignee to pick labels and epic consistent with other related logging and monitoring work.

dsotirho-ucsc commented 1 year ago

@hannes-ucsc: "I think that the S3 access logs and the S3 CloudTrail data events completely cover all requests made to CF distributions. Spike to confirm."