| name | cis-aws-storage-6.12 |
| description | Ensure CloudWatch Metrics for AWS EDR |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","cloudwatch","monitoring","metrics","logging","alerting"] |
| cis_id | 6.12 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.9","cis-aws-storage-6.13"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.12: Ensure CloudWatch Metrics for AWS EDR (Manual)
Profile Applicability
Description
Set up and monitor AWS CloudWatch metrics for Endpoint Detection and Response (EDR) to track and analyze the performance and security of your AWS environment. This involves configuring CloudWatch to collect detailed logs and metrics on EDR activities, such as threat detections, response actions, and system health. Regularly review these metrics to identify trends, anomalies, and potential security issues, enabling proactive management and timely responses to ensure the effectiveness of your EDR solution.
Rationale
Implementing AWS CloudWatch metrics for Endpoint Detection and Response (EDR) is essential for maintaining a secure and efficient AWS environment. By collecting detailed logs and metrics on EDR activities, you gain valuable insights into the performance and health of your security measures. Regular review of these metrics allows for the early detection of trends, anomalies, and potential security threats, enabling proactive management and swift responses to maintain the integrity and effectiveness of your EDR solution. This continuous monitoring ensures that your security posture remains robust and adaptive to evolving threats.
Impact
CloudWatch monitoring provides:
- Visibility into EDR performance
- Early detection of issues
- Trend analysis capabilities
- Anomaly detection
- Proactive management capabilities
- Audit trail for compliance
Requirements:
- CloudWatch log group configuration
- Metric collection setup
- Alarm configuration
- Dashboard creation
- Log insights queries
- Event rule configuration
Audit Procedure
Via AWS Console
-
Sign in to the AWS Management Console:
-
Navigate to CloudWatch:
- In the AWS Management Console, navigate to the CloudWatch service.
-
Create a CloudWatch Log Group:
- Select Logs from the navigation pane.
- Click on Create log group.
- Enter a name for the log group and click Create.
-
Configure AWS EDR to Send Logs to CloudWatch:
- Go to the AWS EDR (Elastic Disaster Recovery) console.