Skip to main content

πŸ’Ό CC6.1-11 Protects Encryption Keys

Description​

Processes are in place to protect encryption keys during generation, storage, use, and destruction.

Similar​

  • Internal
    • ID: dec-c-0e42ea42

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (8)​

PolicyLogic CountFlags
πŸ“ AWS KMS Symmetric CMK Rotation is not enabled 🟒1🟒 x6
πŸ“ Azure Diagnostic Setting Logs export to Storage Account not encrypted with Customer-managed key 🟒1🟒 x6
πŸ“ Azure Key Vault Soft Delete and Purge Protection functions are not enabled 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Azure Storage Account With Critical Data is not encrypted with customer managed key 🟒🟒 x3

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-0be4dfe51
βœ‰οΈ dec-x-0feec7902
βœ‰οΈ dec-x-4d6fee7a1
βœ‰οΈ dec-x-5c3c20671
βœ‰οΈ dec-x-82ca41272
βœ‰οΈ dec-x-aef11ebd1