Evaluates whether the origin of a KMS customer master key (CMK) is Alibaba Cloud rather than an external source. A CMK with a non-external origin is compliant.
Scenarios
Alibaba Cloud-origin CMKs offer stronger security, reliability, simpler management, lower cost, and greater flexibility, and help avoid potential legal risks associated with external key material.
Risk level
Default risk level: medium.
You can change the risk level when you apply this rule.
Compliance evaluation logic
-
The CMK origin is Alibaba Cloud: Compliant.
-
The CMK origin is external: Non-compliant.
Rule details
|
Parameter |
Description |
|
Rule name |
kms-key-origin-not-external |
|
Rule identifier |
|
|
Tag |
KMS, Key |
|
Automatic remediation |
Not supported |
|
Trigger type |
Configuration change |
|
Supported resource type |
KMS CMK |
|
Input parameter |
None |