cloudwatch-log-group-encrypted
Checks if a log group in Amazon CloudWatch Logs is encrypted with an AWS Key Management Service (KMS) key. The rule is NON_COMPLIANT if no AWS KMS key is configured on the log groups.
Identifier: CLOUDWATCH_LOG_GROUP_ENCRYPTED
Trigger type: Periodic
AWS Region: All supported AWS regions except China (Beijing), Asia Pacific (Jakarta), Middle East (UAE), Asia Pacific (Hyderabad), Asia Pacific (Osaka), Asia Pacific (Melbourne), Europe (Spain), China (Ningxia), Europe (Zurich) Region
Parameters:
- KmsKeyId (Optional)
- Type: String
-
Amazon Resource Name (ARN) of AWS Key Management Service (KMS) key that is used to encrypt the CloudWatch Logs log group.
AWS CloudFormation template
To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.