DAT-04.2: Customer managed keys should not be shared across different cloud provider services and should be scoped to least privilege. Key access policies should only allow specific IAM entities and never contain wildcards without conditions.
  • Control automation: Automated
  • AWS control specification: KMS key policy should not contain a principle wildcard or support use by more than one Amazon service
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: KMS key policy should not contain a principle wildcard or support use by more than one Amazon service
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none