All Products
Search
Document Center

Key Management Service:Enable security audit

Last Updated:Jun 20, 2026

After you enable security audit, operational information from your HSM instances is automatically saved to Object Storage Service (OSS) in a specific format to meet compliance and audit requirements. These audit logs contain information about operations such as registering administrators, adding keys, and exporting keys.

Prerequisites

  • You have purchased a cryptographic machine. For more information, see Purchase a Cryptographic Machine.

  • You have enabled OSS and created a bucket. For more information, see Get started by using the OSS console.

    Important
    • The bucket must be in the same region where you plan to enable security audit.

    • Do not delete the OSS bucket while security audit is enabled. Otherwise, audit log delivery fails.

Limitations

  • Security audit is a regional feature and cannot be enabled across regions. For example, if you have HSM instances in both region A and region B, you must enable security audit for each region separately.

  • Security audit is currently a beta feature and is available only for GVSM and EVSM instances.

  • Security audit is supported in the following regions: China (Hangzhou), China (Shanghai), China (Beijing), China (Shenzhen), and China (Chengdu).

Procedure

  1. Go to the Security Audit Service Beta page of the CloudHSM console. In the top navigation bar, select the destination region.

  2. On the Security Audit page, click Enable Security Audit, and then click Authorize.

    When you click Authorize, Cloud Hardware Security Module automatically creates the AliyunServiceRoleForHSMLogDelivery service-linked role. This role grants Cloud Hardware Security Module read and write permissions to your OSS buckets. For more information, see Service-linked roles for Cloud Hardware Security Module.

  3. From the OSS Bucket drop-down list, select the bucket for storing HSM instance audit logs, and then click OK.

    To create a bucket, click Create in Console to open the OSS console, where you can create a bucket in the same region.

Result

On the Security Audit page, the switch turns green and displays Enabled. The Audit Log Delivery Rule section shows the bucket that stores the audit logs for all HSM instances in the current region.

A blue notification bar indicates that the feature is in beta and delivers logs only for EVSM and GVSM instances. The system delivers logs daily to your selected OSS bucket. Logs are stored in a path that includes the -audit-log suffix. You can manage the lifecycle of the log files by configuring OSS lifecycle management rules.

Disable security audit

To disable security audit, on the Security Audit page, click the switch next to Enabled, and then click Close in the Disable Security Audit dialog box.