All Products
Search
Document Center

Cloud Config:Ensure KMS keys are not from external sources

Last Updated:Jun 08, 2026

Evaluates whether the origin of a KMS customer master key (CMK) is Alibaba Cloud rather than an external source. A CMK with a non-external origin is compliant.

Scenarios

Alibaba Cloud-origin CMKs offer stronger security, reliability, simpler management, lower cost, and greater flexibility, and help avoid potential legal risks associated with external key material.

Risk level

Default risk level: medium.

You can change the risk level when you apply this rule.

Compliance evaluation logic

  • The CMK origin is Alibaba Cloud: Compliant.

  • The CMK origin is external: Non-compliant.

Rule details

Parameter

Description

Rule name

kms-key-origin-not-external

Rule identifier

kms-key-origin-not-external

Tag

KMS, Key

Automatic remediation

Not supported

Trigger type

Configuration change

Supported resource type

KMS CMK

Input parameter

None