Skip to main content

πŸ’Ό Cryptographic Configuration

  • Contextual name: πŸ’Ό Cryptographic Configuration
  • ID: /frameworks/cloudaware/secret-and-certificate-governance/cryptographic-configuration
  • Located in: πŸ’Ό Secret & Certificate Governance

Description​

Policies for identifying resources that do not adhere to configuration best practices for keys/secrets/certificates.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (8)​

PolicyLogic CountFlags
πŸ“ AWS ACM Certificate with Wildcard Domain Name 🟒1🟒 x6
πŸ“ AWS ACM RSA Certificate key length is less than 2048 bits 🟒1🟒 x6
πŸ“ AWS CloudTrail Disable CMK or Schedule CMK Deletion Events Monitoring is not enabled 🟒🟒 x3
πŸ“ Google API Key is not restricted for unspecified hosts and apps 🟒🟒 x3
πŸ“ Google API Key is not restricted for unused APIs 🟒1🟒 x6
πŸ“ Google Cloud DNS Managed Zone DNSSEC Key-Signing Algorithm is RSASHA1 🟒1🟒 x6
πŸ“ Google Cloud DNS Managed Zone DNSSEC Zone-Signing Algorithm is RSASHA1 🟒1🟒 x6
πŸ“ Google Project has API Keys 🟒1🟠 x1, 🟒 x5