DAT-03.2: By default, most services in most cloud providers encrypt data using default keys. This meets the requirement for basic compliance and security, but for some data, a customer-managed key (CMK) is more appropriate. Major cloud providers support using your own key (via their key management system) for different services. This can improve security not because it protects from the cloud provider accessing your data, but because splitting the key from the repository reduces inadvertent disclosures and supports separation of duties internally because access to the data and access to the keys can be split. To meet the requirements for Level 3 maturity, only some CMKs in some deployments is required.
  • Control automation: Automated
  • AWS control specification: * KMS is used
  • A CMK exists NOTE: This check should pass even if only some accounts in the organization have any CMKs
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: * KMS is used
  • A CMK exists NOTE: This check should pass even if only some accounts in the organization have any CMKs
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none