All Products
Search
Document Center

Key Management Service:Enable security audit

Last Updated:Mar 31, 2026

Security audit stores the running data of your Cloud Hardware Security Module (HSM) instances as audit logs in an Object Storage Service (OSS) bucket, helping you meet compliance and audit requirements. Once enabled, all HSM instances in the current region deliver their logs to the OSS bucket you select.

Important

The OSS bucket must be in the same region as the HSMs you want to audit. Do not delete the bucket after enabling security audit — deleting it interrupts log delivery.

Limitations

  • Security audit is a beta feature, available only for general virtual security modules (GVSMs) and electronic virtual security modules (EVSMs).

  • Supported regions: China (Hangzhou), China (Shanghai), China (Beijing), China (Shenzhen), and China (Chengdu).

  • Security audit is region-scoped. To audit HSMs in multiple regions, enable it separately in each region.

What the audit logs cover

The audit logs record key operations performed on your HSMs, including:

  • Registering administrators

  • Adding keys and exporting keys

Logs are stored as files in your OSS bucket and can be used for compliance and audit requirements.

Prerequisites

Before you begin, make sure you have:

Enable security audit

  1. Log on to the Cloud Hardware Security Module console and click Security Audit Beta in the left navigation pane.

  2. On the Security Audit page, click Enable Security Audit, then click Authorize. After authorization, HSM automatically creates a service-linked role named AliyunServiceRoleForHSMLogDelivery with read and write permissions on your OSS bucket. For details, see Service-linked role for HSM.

    Security Audit page after clicking Enable and Authorize

  3. In the OSS Bucket drop-down list, select the bucket where you want to store HSM audit logs, then click OK. When the switch turns green and Enabled is displayed, security audit is active. Audit logs for all HSM instances in the current region are delivered to the bucket shown in the Audit Log Delivery Rule section.

    Security Audit Service page with OSS Bucket selector

    Successful activation — green switch and Enabled status

Disable security audit

On the Security Audit page, click the switch next to Enabled. In the Disable Security Audit dialog box, click Close.