Logging and monitoring

Create a Metric Alarm and Filter for IAM policy changes


Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. Monitoring changes to IAM policies will help ensure authentication and authorization controls remain intact.
  • Recommended Mitigation

    It is recommended that a metric filter and alarm be established changes made to Identity and Access Management (IAM) policies.