cloudwatch-log-group-encrypted - AWS Config

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

cloudwatch-log-group-encrypted

Checks if a log group in Amazon CloudWatch Logs is encrypted with a AWS Key Management Service (KMS) managed Customer Master Keys (CMK). The rule is NON_COMPLIANT if no AWS KMS CMK is configured on the log groups.

Identifier: CLOUDWATCH_LOG_GROUP_ENCRYPTED

Trigger type: 定期的

AWS Region: All supported AWS regions except China (Beijing), China (Ningxia) Region

パラメータ:

KmsKeyId (Optional)
タイプ: 文字列

Amazon Resource Name (ARN) of AWS Key Management Service (KMS) key that is used to encrypt the CloudWatch Logs log group.

AWS CloudFormation テンプレート

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.