OSS Bucket Logging Enabled
ID: rule:aliyun:oss-bucket-logging-enabled
Severity: medium
Description
OSS buckets should have logging enabled to track access and operations. Logging helps with security auditing, troubleshooting, and compliance requirements.
Reason for Violation
The OSS bucket does not have logging enabled, which makes it difficult to track access and operations for security and compliance purposes.
Recommendation
Enable logging for the OSS bucket by configuring the LoggingConfiguration property with TargetBucket and optionally TargetPrefix.
Resource Types
ALIYUN::OSS::Bucket