More Info:

Ensure that your Amazon Secrets Manager secrets (i.e. database credentials, API keys, OAuth tokens, etc) are encrypted with Amazon KMS Customer Master Keys (CMKs) instead of default encryption keys that Secrets Manager service creates for you, in order to have a more granular control over secret data encryption and decryption process, and meet compliance requirements.

Risk Level

High

Address

Security

Compliance Standards

ISO27001, HIPAA, NISTCSF, PCIDSS

Triage and Remediation

Remediation

Using Console

Additional Reading: