Description

To ensure all AWS accounts within an organization send AWS CloudTrail logs to a centralized Amazon S3 logging bucket and to enforce this configuration for any future accounts, the following set of actions should be implemented.

Steps

  1. Create and Configure a New Trail
  2. Apply the Trail to the Organization
  3. Prevent Deletion or Stopping of CloudTrail

Rationale

By creating a trail in the management account and applying it to the organization, you ensure that all member accounts, both existing and future, are covered. Additionally, the SCP prevents any accidental or intentional changes that could disable or remove the CloudTrail logging.