Skip to main content

OSS Bucket Logging Enabled

ID: rule:aliyun:oss-bucket-logging-enabled
Severity: medium

Description

OSS buckets should have logging enabled to track access and operations. Logging helps with security auditing, troubleshooting, and compliance requirements.

Reason for Violation

The OSS bucket does not have logging enabled, which makes it difficult to track access and operations for security and compliance purposes.

Recommendation

Enable logging for the OSS bucket by configuring the LoggingConfiguration property with TargetBucket and optionally TargetPrefix.

Resource Types

  • ALIYUN::OSS::Bucket