Configuration

S3 bucket with lifecycle

Require lifecycle policy on S3 buckets for things like logs (1 yr deletion recommended)

Summary

Compliance initiatives almost always want logs for 1 year. Keeping logs longer than that can be a legal liability should something happen at your company. If you have the logs you will be required to look at them, should you need to investigate. This also helps with cost of storing your data in S3. If you don't lifecycle the logs out, consider moving them to a different class of storage like glacier to cut cost.

Applicable To

Always

Resources

S3

Maturity

Medium

Functions
Cost Management
CSPS

AWS

Author

Will Bengtson

Back to Home