Ensure CloudTrail is Logging Management Events
AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log, continuously monitor, and retain account activity related to actions across your AWS infrastructure. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. Since this holds all audit logs, it is important to have a log of all changes that have happened in your AWS account. This is why CloudTrail logging management events is a security best practice. Having a full inventory of your CloudTrails with current logging status across all of your accounts can help with NIST, GDPR & PCI-DSS compliance.