Kanji
・Ingeniero Cloud / Freelance ・Nacido en 1993 ・De Ehime / Residente en Shibuya, Tokio ・5 años de experiencia en AWS Detalles del perfil
Índice
cfn-guard validate \ --rules ~/cis-aws-benchmark-level-1.guard \ --data ./template.yml
The following CloudFormation template creates a bucket for storing audit logs output by AWS services.
The sources of the accumulated audit logs are AWS Config, AWS CloudTrail, Amazon GuardDuty, and Amazon VPC Flow Logs.
The log retention period is one year, and the retention period for multipart uploads and noncurrent files is 7 days.
A separate bucket is created for server access logs, which is set as the log destination for the audit log bucket.
As described in Amazon S3 server access logging now supports automatic date-based partitioning , server access logs can be partitioned by date, so the path is cut at the S3 event time.
The URLs of the sites referenced when designing the bucket policy and KMS key policy are included in the comments.
In the referenced documents, the Condition fields aws:SourceArn and aws:SourceAccount used the AWS account and resources of the log source, but these have been omitted in the following templates. At a minimum, access from IAM users and roles is denied, as the AWS service name is restricted by the Principal .
Condition
aws:SourceArn
aws:SourceAccount
Principal
There is a risk of logs being output from unexpected AWS accounts due to design mistakes, so please add Condition statements as needed.
The design is based primarily on CIS and CFN_NAG rules.
AWSTemplateFormatVersion: 2010-09-09 Resources: AuditLogBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-audit-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: KMSMasterKeyID: !GetAtt AuditLogKey01.Arn SSEAlgorithm: aws:kms OwnershipControls: Rules: - ObjectOwnership: BucketOwnerEnforced LifecycleConfiguration: Rules: - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 - Status: Enabled ExpirationInDays: 365 Prefix: / PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true VersioningConfiguration: Status: Enabled LoggingConfiguration: DestinationBucketName: !Ref ServerAccessLogBucket01 TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime AuditLogBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AuditLogBucket01 PolicyDocument: Version: 2012-10-17 Statement: # Reference: https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-policy.html - Sid: AWSConfigAclCheck Effect: Allow Principal: Service: config.amazonaws.com Action: - s3:GetBucketAcl Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01} - Sid: AWSConfigWrite Effect: Allow Principal: Service: config.amazonaws.com Action: - s3:PutObject - s3:PutObjectAcl Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01}/* # Reference: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/create-s3-bucket-policy-for-cloudtrail.html - Sid: AWSCloudTrailAclCheck Effect: Allow Principal: Service: cloudtrail.amazonaws.com Action: - s3:GetBucketAcl Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01} - Sid: AWSCloudTrailWrite Effect: Allow Principal: Service: cloudtrail.amazonaws.com Action: - s3:PutObject Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01}/AWSLogs/* Condition: StringEquals: s3:x-amz-acl: bucket-owner-full-control # Reference: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_exportfindings.html#guardduty_exportfindings-s3-policies - Sid: AllowPutObject Effect: Allow Principal: Service: guardduty.amazonaws.com Action: s3:PutObject Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01}/* - Sid: AllowGetBucketLocation Effect: Allow Principal: Service: guardduty.amazonaws.com Action: s3:GetBucketLocation Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01} # Reference: https://docs.aws.amazon.com/vpc/latest/tgw/flow-logs-s3.html#flow-logs-s3-permissions - Sid: VPCFlowLogsWrite Effect: Allow Principal: Service: delivery.logs.amazonaws.com Action: - s3:PutObject Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01}/* Condition: StringEquals: s3:x-amz-acl: bucket-owner-full-control - Sid: AWSLogDeliveryAclCheck Effect: Allow Principal: Service: delivery.logs.amazonaws.com Action: - s3:GetBucketAcl - s3:ListBucket Resource: !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01} # Reference: https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01} - !Sub arn:${AWS::Partition}:s3:::${AuditLogBucket01}/* Condition: Bool: aws:SecureTransport: false ServerAccessLogBucket01: Type: AWS::S3::Bucket Metadata: cfn_nag: rules_to_suppress: - id: W35 reason: There is no need to record the server access log bucket itself guard: SuppressedRules: - S3_BUCKET_LOGGING_ENABLED # There is no need to record the server access log bucket itself Properties: BucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: # Since SSE-KMS is not supported, use SSE-S3 # Reference: https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-server-access-logging.html ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 OwnershipControls: Rules: - ObjectOwnership: BucketOwnerEnforced LifecycleConfiguration: Rules: - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 - Status: Enabled ExpirationInDays: 365 Prefix: / PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true VersioningConfiguration: Status: Enabled ServerAccessLogBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref ServerAccessLogBucket01 PolicyDocument: Version: 2012-10-17 Statement: # Reference: https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-server-access-logging.html#grant-log-delivery-permissions-general - Sid: S3ServerAccessLogsPolicy Effect: Allow Principal: Service: logging.s3.amazonaws.com Action: s3:PutObject Resource: !Sub arn:${AWS::Partition}:s3:::${ServerAccessLogBucket01}/* # Reference: https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${ServerAccessLogBucket01} - !Sub arn:${AWS::Partition}:s3:::${ServerAccessLogBucket01}/* Condition: Bool: aws:SecureTransport: false AuditLogKey01: Type: AWS::KMS::Key UpdateReplacePolicy: Retain DeletionPolicy: Retain Properties: EnableKeyRotation: true RotationPeriodInDays: 365 KeyPolicy: Version: 2012-10-17 Statement: - Sid: EnableIAMUserPermissions Effect: Allow Principal: AWS: !Ref AWS::AccountId Action: kms:* Resource: '*' # Reference: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_exportfindings.html - Sid: AllowGuardDutyKey Effect: Allow Principal: Service: guardduty.amazonaws.com Action: kms:GenerateDataKey Resource: '*'
s3:PutObject
s3:GetBucketLocation
AWSTemplateFormatVersion: 2010-09-09 Resources: AthenaBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-athena-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 LifecycleConfiguration: Rules: - Status: Enabled ExpirationInDays: 45 Prefix: athena/ - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true LoggingConfiguration: DestinationBucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime VersioningConfiguration: Status: Enabled AthenaBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AthenaBucket01 PolicyDocument: Version: 2012-10-17 Statement: - Sid: AllowAthenaGetBucketLocation Effect: Allow Principal: Service: - !Sub athena.${AWS::Region}.amazonaws.com Action: - s3:GetBucketLocation - s3:PutObject Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* # Reference: https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* Condition: Bool: aws:SecureTransport: false