Description
CloudTrail encrypts log files with S3-managed keys by default. A customer managed KMS key allows separate control of key policy and decryption permissions; an absent KMSKeyId does not mean the logs are stored in plaintext.
Potential impact
An environment requiring customer managed keys may not meet its key-access or audit requirements.
Remediation
Specify KMSKeyId when a customer managed key is required. Configure CloudTrail’s key permissions and log readers’ decryption permissions, then verify log delivery.
Examples
The examples add a KMS key to an existing trail. Replace the key ARN with the actual key and configure its policy separately.
Before
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
After
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
KMSKeyId: arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012