All Products
Search
Document Center

Cloud Config:kms-secret-last-rotation-date-check

Last Updated:Jun 22, 2026

Evaluates whether Key Management Service (KMS) secrets have automatic rotation enabled and whether rotation is performed based on the specified rotation period. If so, the evaluation result is Compliant. This rule does not apply to generic secrets because periodic rotation cannot be enabled for generic secrets in KMS.

Scenarios

Enable automatic rotation for KMS secrets to reduce the risk of secret leaks and improve system security. Ensure that your applications are compatible with automatic rotation.

Risk level

Default risk level: high.

You can change the risk level based on your business requirements when you apply this rule.

Compliance evaluation logic

  • If automatic rotation is enabled for KMS secrets and rotation is performed based on the specified rotation period, the evaluation result is Compliant.

  • This rule does not apply to generic secrets because periodic rotation cannot be enabled for generic secrets in KMS.

Rule details

Parameter

Description

Rule Template Name

kms-secret-last-rotation-date-check

Rule Template Identifier

kms-secret-last-rotation-date-check

Tag

Secret

Automatic remediation

Not supported

Invoke Type

Periodic: Every 24 hours

Supported resource type

KMS secret (ACS::KMS::Secret)

Input parameter

N/A

Non-compliance remediation

Enable automatic rotation for KMS secrets and ensure rotation is performed based on the specified rotation period. For more information, seeOverview.