turbot/alicloud_compliance

Control: 2.10 Ensure log monitoring and alerts are set up for RAM Role changes

Description

It is recommended that a query and alarm should be established for RAM Role creation, deletion and updating activities.

Remediation

Perform the following to ensure the log monitoring and alerts are set up for RAM Role Changes:

From Console

  1. Logon to SLS Console.
  2. Click Log Service Audit Service in the navigation pane.
  3. Go to Access to Cloud Products > Global Configuration page.
    • Select a location of project for logs.
    • Check the Action Trail and configure a proper days.
    • Click Save to save the changes.
  4. Go to Access to Cloud Products > Global Configurations click Central Project.
  5. Select Log Management > Actiontrail Log.
  6. In the search/analytics console, input below query
("event.serviceName": ResourceManager or "event.serviceName": Ram) and ("event.eventName": CreatePolicy or "event.eventName": DeletePolicy or "event.eventName": CreatePolicyVersion or "event.eventName": UpdatePolicyVersion or "event.eventName": SetDefaultPolicyVersion or "event.eventName": DeletePolicyVersion) | select count(1) as c
  1. Create a dashboard and set alert for the query result.

Usage

Run the control in your terminal:

powerpipe control run alicloud_compliance.control.cis_v100_2_10

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run alicloud_compliance.control.cis_v100_2_10 --share

SQL

This control uses a named query:

manual_control

Tags