DAT-03.2: By default, most services in most cloud providers encrypt data using default keys. This meets the requirement for basic compliance and security, but for some data, a customer-managed key (CMK) is more appropriate. Major cloud providers support using your own key (via their key management system) for different services. This can improve security not because it protects from the cloud provider accessing your data, but because splitting the key from the repository reduces inadvertent disclosures and supports separation of duties internally because access to the data and access to the keys can be split.
To meet the requirements for Level 3 maturity, only some CMKs in some deployments is required.
Control automation: Automated
AWS control specification: * KMS is used
A CMK exists
NOTE: This check should pass even if only some accounts in the organization have any CMKs
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: * KMS is used
A CMK exists
NOTE: This check should pass even if only some accounts in the organization have any CMKs
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none