πΌ A.10.1.2 Key management
- Contextual name: πΌ A.10.1.2 Key management
- ID:
/frameworks/iso-iec-27001-2013/10/01/02
- Located in: πΌ A.10.1 Cryptographic controls
Descriptionβ
A policy on the use, protection and lifetime of cryptographic keys shall be developed and implemented through their whole lifecycle
Similarβ
- Internal
- ID:
dec-c-df02197d
- ID:
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (11)β
Policy | Logic Count | Flags |
---|---|---|
π AWS IAM User Access Keys are not rotated every 90 days or less π’ | 1 | π’ x6 |
π AWS IAM User has more than one active access key π’ | 1 | π’ x6 |
π AWS IAM User with console and programmatic access set during the initial creation π’ | π’ x3 | |
π AWS KMS Symmetric CMK Rotation is not enabled π’ | 1 | π’ x6 |
π Azure Key Vault Soft Delete and Purge Protection functions are not enabled π’ | 1 | π’ x6 |
π Azure Non-RBAC Key Vault stores Keys without expiration date π’ | 1 | π’ x6 |
π Azure Non-RBAC Key Vault stores Secrets without expiration date π’ | 1 | π’ x6 |
π Azure RBAC Key Vault stores Keys without expiration date π’ | 1 | π’ x6 |
π Azure RBAC Key Vault stores Secrets without expiration date π’ | 1 | π’ x6 |
π Azure SQL Server Transparent Data Encryption Protector is not encrypted with Customer-managed key π’ | 1 | π’ x6 |
π Azure Storage Account With Critical Data is not encrypted with customer managed key π’ | π’ x3 |
Internal Rulesβ
Rule | Policies | Flags |
---|---|---|
βοΈ dec-x-0be4dfe5 | 1 | |
βοΈ dec-x-0feec790 | 2 | |
βοΈ dec-x-4d6fee7a | 1 | |
βοΈ dec-x-82ca4127 | 2 | |
βοΈ dec-x-230b5e35 | 1 | |
βοΈ dec-x-30795016 | 1 | |
βοΈ dec-x-aef11ebd | 1 | |
βοΈ dec-x-b10e98af | 1 | |
βοΈ dec-x-bcb0c78f | 1 |