AWS CloudTrail records your API calls and provides log files for verification and auditing purposes. AWS is enhancing this service by supporting two new features: Encryption for SSE-KMS and Log File Integrity Validation.
CloudTrail saves your log files in an S3 bucket which is encrypted with Server Side Encryption (SSE). You can further secure that bucket by encrypting it with an AWS Key Management Service (KMS) key that you provide, effectively increasing its security.
On the other hand, if you want to verify the integrity of your log file, you can now do so by changing the setting in your CloudTrail configuration screen. Once enabled, you can then determine whether or not your log has been tampered with. The full description of this feature can be found here.
Cloud security is a shared responsibility between the user and the cloud provider. If you want to learn more about how to increase the security of your business within the cloud, contact our AWS-certified experts here in PolarSeven.
The post AWS CloudTrail: Encryption & Log File Integrity Verification appeared first on PolarSeven Cloud Consulting.