Evaluates whether Key Management Service (KMS) secrets have automatic rotation enabled and whether rotation is performed based on the specified rotation period. If so, the evaluation result is Compliant. This rule does not apply to generic secrets because periodic rotation cannot be enabled for generic secrets in KMS.
Scenarios
Enable automatic rotation for KMS secrets to reduce the risk of secret leaks and improve system security. Ensure that your applications are compatible with automatic rotation.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
-
If automatic rotation is enabled for KMS secrets and rotation is performed based on the specified rotation period, the evaluation result is Compliant.
-
This rule does not apply to generic secrets because periodic rotation cannot be enabled for generic secrets in KMS.
Rule details
|
Parameter |
Description |
|
Rule Template Name |
kms-secret-last-rotation-date-check |
|
Rule Template Identifier |
|
|
Tag |
Secret |
|
Automatic remediation |
Not supported |
|
Invoke Type |
Periodic: Every 24 hours |
|
Supported resource type |
KMS secret (ACS::KMS::Secret) |
|
Input parameter |
N/A |
Non-compliance remediation
Enable automatic rotation for KMS secrets and ensure rotation is performed based on the specified rotation period. For more information, seeOverview.