Cloudanix home pagelight logodark logo
  • Community
  • Login
  • Login
  • Overview
  • AWS
  • Azure
  • GCP
  • GitHub
  • On-Demand Scan
  • Kubernetes
  • Integrations
  • AWS Introduction
    • Security of your AWS Account
    AWS Pricing
    • AWS Services which determine your cost
    AWS Threats
    • Getting Started with AWS Realtime Events
    AWS Misconfigurations
    • Getting Started with AWS Audit
    • Permissions required for Misconfigurations Detection
    • API Gateway Audit
    • Cloudformation Audit
    • CloudFront Audit
    • CloudTrail Audit
    • Cloudwatch Audit
    • DynamoDB Audit
    • EC2 Audit
    • Elastic Search Audit
    • ELB Audit
    • IAM Audit
    • KMS Audit
    • Kubernetes Audit
    • Lambda Audit
    • RDS Audit
    • Redshift Audit
    • Route53 Audit
    • S3 Audit
    • Security Groups Audit
    • SES Audit
    • SNS Audit
    • IAM Deep Dive
    • App Sync Audit
    • Code Build Audit
    • Open Search Audit
    • Shield Audit
    • SQS Audit
    On this page
    • Checks performed
    AWS Misconfigurations

    KMS Audit

    ​
    Checks performed

    • App-tier KMS Key Should Be In Use
    • KMS Keys Should Not Allow Unknown Cross Account Access
    • Database-tier KMS Key Should Be In Use
    • KMS Keys Should Not Be Exposed
    • KMS Key Rotation Should Be Enabled
    • KMS Customer Master Key Should Be In Use
    • KMS Key Policies Should Be Designed To Limit Number Of KMS Admins
    • KMS Keys Scheduled For Deletion Should Be Recovered
    • Secrets Manager Should Be In Use
    • Secret Manager Secrets Rotation Enabled
    • Secrets Manager Secrets Should Be Rotated Frequently
    • Existence of specific AWS KMS CMKs
    • Existence Of Specific AWS KMS CMKs
    • Unused Customer Master Key Should Be Removed
    • Web-tier KMS Key Should Be In Use
    • Secrets Manager Secrets Should Be Encrypted With CMKs
    • Secrets Manager Secrets Rotation Enabled
    • Secrets Manager Secrets Rotation Enabled
    • Secrets Manager Should Be In Use
    IAM AuditKubernetes Audit
    githubtwitter
    Powered by Mintlify
    Assistant
    Responses are generated using AI and may contain mistakes.