Description
CloudWatch Logs encrypts stored log data by default. Omitting kms_key_id does not mean logs are stored in plaintext. However, default encryption may not satisfy an organization's key-policy and lifecycle requirements when a customer-managed KMS key is required.
Logs can contain operational details, error messages, user activity and security events. Review the required level of key control together with permissions to read the logs.
Potential impact
Where customer-managed keys are mandatory, a log group whose key policy is not directly managed may fail encryption requirements. Associating a KMS key does not resolve excessive log-read permissions or secrets written to logs.
Remediation
- If a customer-managed key is required, set
kms_key_idto its ARN. Configure the key policy and permissions so CloudWatch Logs can use it. - The association applies to logs ingested afterward. Retain the previous keys and permissions needed to read existing logs.
- Limit log-read permissions and retention, and prevent secrets from being written to logs.
Examples
Default encryption at rest
resource "aws_cloudwatch_log_group" "example" {
name = "Yada"
tags = {
Environment = "production"
Application = "serviceA"
}
retention_in_days = 1
}
This uses the service's default encryption without specifying a customer-managed key.
Specify a customer-managed key
resource "aws_cloudwatch_log_group" "example" {
name = "Yada"
tags = {
Environment = "production"
Application = "serviceA"
}
retention_in_days = 1
kms_key_id = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
Replace the example ARN with the actual key ARN and check key-use permissions. This association does not re-encrypt previously ingested logs with the new key.