πΌ [SecretsManager.3] Remove unused Secrets Manager secrets
- Contextual name: πΌ [SecretsManager.3] Remove unused Secrets Manager secrets
- ID:
/frameworks/aws-fsbp-v1.0.0/secrets-manager/03
- Located in: πΌ Secrets Manager
Descriptionβ
Deleting unused secrets is as important as rotating secrets. Unused secrets
can be abused by their former users, who no longer need access to these secrets.
Also, as more users get access to a secret, someone might have mishandled
and leaked it to an unauthorized entity, which increases the risk of abuse.
Deleting unused secrets helps revoke secret access from users who no longer
need it. It also helps to reduce the cost of using Secrets Manager. Therefore,
it is essential to routinely delete unused secrets.
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|