Skip to main content

πŸ’Ό Expiration Management

  • Contextual name: πŸ’Ό Expiration Management
  • ID: /frameworks/cloudaware/secret-and-certificate-governance/expiration-management
  • Located in: πŸ’Ό Secret & Certificate Governance

Description​

Policies for identifying resources that do not implement expiration and rotation management procedures for keys, secrets, and certificates.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (12)​

PolicyLogic CountFlags
πŸ“ AWS ACM Certificate expires in the next 7 days 🟒1🟒 x6
πŸ“ AWS ACM Certificate Expired 🟒1🟒 x6
πŸ“ AWS IAM Server Certificate is expired 🟒1🟒 x6
πŸ“ AWS KMS Symmetric CMK Rotation is not enabled 🟒1🟒 x6
πŸ“ Azure Key Vault Automatic Key Rotation is not enabled 🟠🟒1🟠 x1, 🟒 x5
πŸ“ Azure Non-RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Google API Key is not rotated every 90 days 🟒1🟒 x6
πŸ“ Google IAM Service Account User-Managed Key is not rotated every 90 days 🟒1🟒 x6
πŸ“ Google KMS Crypto Key is not rotated every 90 days 🟒1🟒 x6