DAT-04.2: Customer managed keys should not be shared across different cloud provider services and should be scoped to least privilege. Key access policies should only allow specific IAM entities and never contain wildcards without conditions.
Control automation: Automated
AWS control specification: KMS key policy should not contain a principle wildcard or support use by more than one Amazon service
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: KMS key policy should not contain a principle wildcard or support use by more than one Amazon service
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none