CloudTrail logs without a configured KMS key

Configure KMS encryption to meet log key-management requirements.

Description

CloudTrail encrypts log files with S3-managed keys by default. A customer managed KMS key allows separate control of key policy and decryption permissions; an absent KMSKeyId does not mean the logs are stored in plaintext.

Potential impact

An environment requiring customer managed keys may not meet its key-access or audit requirements.

Remediation

Specify KMSKeyId when a customer managed key is required. Configure CloudTrail’s key permissions and log readers’ decryption permissions, then verify log delivery.

Examples

The examples add a KMS key to an existing trail. Replace the key ARN with the actual key and configure its policy separately.

Before

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true

After

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true
      KMSKeyId: arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012

References