Ensure that your Amazon CloudTrail trails are configured to use active Simple Notification Service (SNS) topics in order to receive a notification for every log file delivery made to the associated (target) bucket.
excellence
When your CloudTrail trails are not referencing active SNS topics anymore, the cloud service can't send notifications each time Amazon CloudTrail publishes new log files to the associated S3 bucket, therefore you lose the ability to take immediate actions based on the log information received from Amazon CloudTrail.
Audit
To identify CloudTrail trails that are missing the capability to send notifications on log file delivery due to inactive SNS topics, perform the following actions:
Remediation / Resolution
To reconfigure any Amazon CloudTrail trails associated with missing SNS topics, perform the following actions:
References
- AWS Documentation
- AWS CloudTrail FAQs
- Configuring Amazon SNS Notifications for CloudTrail
- Updating a Trail
- AWS Command Line Interface (CLI) Documentation
- cloudtrail
- list-trails
- describe-trails
- update-trail
- sns
- get-topic-attributes
- create-topic
- subscribe
- confirm-subscription
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Check for Missing SNS Topic within Trail Configuration
Risk Level: Medium