Description
CloudTrail logs are essential records of account activity and security events. Log and digest files are encrypted with SSE-S3 even when SSE-KMS is not enabled, so omitting kms_key_id does not imply plaintext storage.
SSE-KMS lets you control KMS decryption permissions in addition to the S3 permissions needed to read logs. Configure it explicitly where audit logs require separate key policies and lifecycle management.
Potential impact
The configuration may not meet an audit requirement for a separate KMS key. Conversely, an incorrect key policy can interrupt delivery or analysts' access, so verify access restrictions together with continuous log collection.
Remediation
- When required, set
kms_key_idto a KMS key in the same Region as the log bucket. - Configure the key policy to allow CloudTrail to encrypt logs and approved analysts to decrypt them. Restrict S3 bucket permissions as well.
- Verify delivery and reading of new logs after the change, and retain keys and permissions needed to read retained logs.
Examples
These excerpts require an actual log bucket and a bucket policy allowing CloudTrail delivery. Replace the bucket name and key ARN for your environment.
Omit the KMS key
resource "aws_cloudtrail" "example" {
name = "trail"
s3_bucket_name = "bucketlog1"
}
No KMS key is explicitly assigned to the trail. This alone does not establish that logs are unencrypted.
Specify a KMS key
resource "aws_cloudtrail" "example" {
name = "trail"
s3_bucket_name = "bucketlog1"
kms_key_id = "arn:aws:kms:us-east-2:123456789012:key/12345678-1234-1234-1234-123456789012"
}
This assigns a KMS key to the same trail. Prepare permissions for CloudTrail and log readers along with the key ARN.