πΌ d. predefined activation and deactivation dates for cryptographic keys, limiting the period of time they remain valid for use. The period of time a cryptographic key remains valid would be commensurate with the risk;
- Contextual name: πΌ d. predefined activation and deactivation dates for cryptographic keys, limiting the period of time they remain valid for use. The period of time a cryptographic key remains valid would be commensurate with the risk;
- ID:
/frameworks/apra-cpg-234/e/5/d
- Located in: πΌ 5 An APRA-regulated entity would typically deploy, where relevant, controls to limit access to cryptographic keys, including:
Descriptionβ
Empty...
Similarβ
- Internal
- ID:
dec-c-e17a05d5
- ID:
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (4)β
Policy | Logic Count | Flags |
---|---|---|
π AWS IAM User Access Keys are not rotated every 90 days or less π’ | 1 | π’ x6 |
π AWS KMS Symmetric CMK Rotation is not enabled π’ | 1 | π’ x6 |
π Azure Non-RBAC Key Vault stores Secrets without expiration date π’ | 1 | π’ x6 |
π Azure RBAC Key Vault stores Secrets without expiration date π’ | 1 | π’ x6 |
Internal Rulesβ
Rule | Policies | Flags |
---|---|---|
βοΈ dec-x-4d6fee7a | 1 | |
βοΈ dec-x-82ca4127 | 2 | |
βοΈ dec-x-bcb0c78f | 1 |