Control: 2.21 Ensure a log monitoring and alerts are set up for OSS bucket policy changes
Description
Real-time monitoring of API calls can be achieved by directing ActionTrail Logs to Log Service and establishing corresponding query and alarms. It is recommended that a query and alarm be established for changes to OSS bucket policies.
Remediation
Perform the following to ensure the log monitoring and alerts are set up for OSS bucket policy changes.
From Console
- Logon to SLS Console.
- Click
Log Service Audit Service
in the navigation pane. - Go to
Access to Cloud Products > Global Configuration
page.- Select a location of project for logs.
- Check the
Action Trail
and configure a proper days. - Click
Save
to save the changes.
- Go to
Access to Cloud Products > Global Configurations
clickCentral Project
. - Select
Log Management > Actiontrail Log
. - In the search/analytics console, input below query
"event.eventName": PutBucketLifecycle or "event.eventName": PutBucketPolicy or "event.eventName": PutBucketCors or "event.eventName": PutBucketEncryption or "event.eventName": PutBucketReplication or "event.eventName":DeleteBucketPolicy or "event.eventName": DeleteBucketCors or "event.eventName": DeleteBucketLifecycle or "event.eventName": DeleteBucketEncryption or "event.eventName": DeleteBucketReplication) | select bucket, count(1) as cnt
- Create a dashboard and set alert for the query result.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_2_21
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_2_21 --share
SQL
This control uses a named query:
manual_control