Ensure that the rotation interval for your AWS Secrets Manager secrets is configured to meet security and compliance requirements. Before this rule runs, the rotation interval (in days) must be configured in the rule settings, on your TrendAI Vision One™ Cloud Risk Management Dashboard. Amazon Secrets Manager rotation feature represents the automatic process that periodically change your secrets information to make it more difficult for attackers to access the services and resources secured with these secrets.
This rule can help you with the following compliance standards:
- APRA
- MAS
For further details on compliance standards supported by TrendAI Vision One™ Cloud Risk Management, see here.
This rule can help you work with the AWS Well-Architected Framework.
By configuring your Amazon Secrets Manager secrets to use the right number of days between secrets rotation (also known as rotation interval), you fulfill the security and compliance requirements defined by your organization.
Note: This rule assumes that the automatic rotation feature is already enabled for your AWS Secrets Manager secrets. If automatic rotation is not currently enabled, follow the steps outlined in this rule to enable the feature.
Audit
To determine if automatic rotation interval is configured correctly for your Amazon Secrets Manager secrets, perform the following actions:
Remediation / Resolution
To configure the automatic rotation interval for your Amazon Secrets Manager secrets in order to meet the security and compliance requirements defined within your organization, perform the following actions:
References
- AWS Documentation
- AWS Secrets Manager FAQs
- What is AWS Key Management Service?
- Rotating Your AWS Secrets Manager Secrets
- Enabling Rotation for an Amazon RDS Database Secret
- AWS Command Line Interface (CLI) Documentation
- secretsmanager
- list-secrets
- describe-secret
- rotate-secret