AWS Config
Developer Guide

cloudwatch-log-group-encrypted

Checks whether a log group in Amazon CloudWatch Logs is encrypted. The rule is NON_COMPLIANT if CloudWatch Logs has a log group without encryption enabled.

Identifier: CLOUDWATCH_LOG_GROUP_ENCRYPTED

Trigger type: Periodic

Parameters:

KmsKeyId

(Optional) Amazon Resource Name (ARN) of an AWS Key Management Service (KMS) key that is used to encrypt the CloudWatch Logs log group.

AWS CloudFormation template

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.