For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/yg4-3in-tkd.md. A documentation index is available at /llms.txt.

CloudTrail logs should be encrypted at rest using KMS CMKs

Description

AWS CloudTrail records AWS API calls, and configuring it to use AWS Key Management Service (KMS) for server-side encryption (SSE) enhances log security. KMS uses Hardware Security Modules (HSMs) for key protection, adding confidentiality controls. Setting up CloudTrail with SSE-KMS ensures only authorized users with S3 read and CMK decrypt permissions can access the logs.

Remediation

For instructions on configuring CloudTrail to use SSE-KMS, refer to the CloudTrail Log File Encryption Guide.