aws-solutions / aws-control-tower-customizations

The Customizations for AWS Control Tower solution combines AWS Control Tower and other highly-available, trusted AWS services to help customers more quickly set up a secure, multi-account AWS environment using AWS best practices.
https://docs.aws.amazon.com/controltower/latest/userguide/cfct-overview.html
Apache License 2.0
354 stars 205 forks source link

Enable "Server Access Logging" on the CloudTrail S3 bucket or have an option to enable it #194

Open Eikistein opened 2 months ago

Eikistein commented 2 months ago

Is your feature request related to a problem? Please describe. S3 bucket access logging should be enabled on the CloudTrail S3 bucket. The fact that is disabled prevents adopters from being compliant with CIS AWS Foundations Benchmark, also see https://docs.aws.amazon.com/securityhub/latest/userguide/cloudtrail-controls.html#cloudtrail-7

Describe the feature you'd like Enable "Server Access Logging" on the CloudTrail S3 bucket OR have an option to have it enabled

Additional context