Property
Languagehcl
Severitylow
CWECWE-778: Insufficient Logging
OWASPA09:2021 - Security Logging and Monitoring Failures
Confidence LevelMedium
Impact LevelLow
Likelihood LevelLow

Description#

Your AWS DocumentDB cluster does not have auditing enabled, meaning activity logs are not being exported to CloudWatch. Without this, you lack visibility into who is accessing or modifying your database.

Impact#

If auditing is not enabled, suspicious or unauthorized actions could go undetected, making it difficult to investigate security incidents, meet compliance requirements, or respond to potential breaches. This lack of monitoring can leave your data and organization at risk.