cloudtrail-all-read-s3-data-event-check - AWS Config

cloudtrail-all-read-s3-data-event-check

Checks if an AWS CloudTrail multi-Region trail is enabled and logs all read S3 data events for your buckets. The rule is NON_COMPLIANT if no multi-Region trail logs all read S3 data event types for all current and future S3 buckets.

Identifier: CLOUDTRAIL_ALL_READ_S3_DATA_EVENT_CHECK

Resource Types: AWS::::Account

Trigger type: Periodic

AWS Region: All supported AWS regions

Parameters:

None

AWS CloudFormation template

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.