Disclaimer: Internal engineering gap-check only. Not a formal QSA assessment. Formal compliance requires a Qualified Security Assessor (QSA). Read-only automated collection; no AWS resources were modified.
Audit logging (CloudTrail), security-event alerting, flow logs, retention and time-sync posture.
CloudTrailCWL alarmsFlow logsRetention
10.2 — CloudTrail Audit Logging
| Check | Value | Status |
|---|
| Logging active | Yes | Compliant |
| Multi-region | Yes | Compliant |
| Log file validation | Yes | Compliant |
| KMS-encrypted | Yes | Compliant |
| CloudWatch Logs integration | NO | Gap |
10.4 — Security Event Alerting (CIS metric-filter alarms)
CloudTrail→CloudWatch Logs metric filters: 0. CloudTrail-metric alarms: 0. CloudTrail CloudWatch Logs integration: NOT enabled — without it, metric-filter alarms on API activity cannot fire.
| Recommended security alarm | Status |
|---|
| Unauthorized API calls | Gap |
| Console sign-in without MFA | Gap |
| Root account usage | Gap |
| IAM policy changes | Gap |
| CloudTrail config changes | Gap |
| Console auth failures | Gap |
| CMK disable/schedule deletion | Gap |
| S3 bucket policy changes | Gap |
| Config changes | Gap |
| Security group changes | Gap |
| NACL changes | Gap |
| Network gateway changes | Gap |
10.2 — VPC Flow Logs
| VPC | Flow Log | Status |
|---|
| vpc-3**** | MISSING | Gap |
| vpc-0**** | Active | Compliant |
Note: SSM Run Command inspection unavailable in this environment (aws-cli send-command incompatibility; prior attempt returned send-failed) — instance-level checks require manual review.
Control Mapping
| Control | Description | Status | Evidence |
|---|
| 10.2.1 | Audit trail enabled for all system components | Compliant | Trail 'auditlog-hipaa' logging=True |
| 10.3.2 | Log file integrity protection (validation) | Compliant | LogFileValidation=True |
| 10.5.1 (Coverage) | Multi-region trail coverage | Compliant | MultiRegion=True |
| 10.4.1 | Security events reviewed / alerted (12 alarm matrix) | Gap | 0/12 CloudTrail security-event alarms configured |
| 10.5.1 (Retention) | Audit history retained ≥12 months | Gap | 50/74 groups ≥365d; 24 never-expire (unset) |
| 10.2.1 (Network) | Network flow logging enabled per VPC | Gap | 1/2 VPCs with active flow logs |
| 10.2.1 (DB) | Database audit logs exported | Compliant | 2/2 DBs export logs to CloudWatch |
| 10.7.1 (Detection) | Failures of critical security controls detected | Compliant | GuardDuty ENABLED |
| 10.6.1 (Time) | Time synchronization on hosts (NTP/chrony) | Needs Review | SSM inspection unavailable — verify chronyd/NTP per instance manually |
Recommendations
HighEnable CloudTrail → CloudWatch Logs integration and create the 12 CIS security metric-filter alarms (unauthorized API calls, root usage, IAM/policy changes, etc.) — currently 0/12 (PCI 10.4.1).
MediumEnable VPC Flow Logs for: vpc-3****.
MediumSet CloudWatch Logs retention to ≥365 days on audit-relevant log groups (many are unset/never-expire).
ProcessDefine and evidence daily log-review procedures (PCI 10.4.1) and 12-month retention with 3 months immediately available (10.5.1).