AWS-Neptune-DB-audit-logs-for-log-export-enable
Severity: Medium
Description: This control ensures that Audit Log type under Log Exports is published to the AWS CloudWatch for the Neptune DB Cluster. These logs can play a vital role in debugging, troubleshooting, detecting malicious activities, and security audits. The "Log exports" option for Neptune Cluster publishes the Audit logs to CloudWatch for further processing and storage. Appropriate logs types should be published to be able to find the source in case of any security incident.
Remediation Steps:
Perform following to configure audit logs for Neptune :
Login to the AWS Management Console at https://console.aws.amazon.com.
Navigate to Neptune console.
In the navigation pane, choose Databases.
Select database Cluster to configure, Choose Modify.
Under the Log exports select audit log type.
Click Continue.
Under the Scheduling of modifications option select Apply Immediately.
Click Modify DB Cluster.
Important:
This control does not apply to AWS GovCloud.
Reference:
Blue Hexagon Proprietary