Data protection

AWS Secrets Manager secret with public access

Platform(s)
Compliance Frameworks
  • Brazilian General Data Protection (LGPD)
  • ,
  • CCPA
  • ,
  • CPRA
  • ,
  • Data Security Posture Management (DSPM) Best Practices
  • ,
  • ISO 27701
  • ,
  • iso_27001_2022
  • ,
  • iso_27002_2022
  • ,
  • Mitre ATT&CK
  • ,
  • NIST 800-171
  • ,
  • NIST 800-53
  • ,
  • Orca Best Practices
  • ,
  • PDPA
  • ,
  • UK Cyber Essentials

Description

AWS Secrets Manager helps you to store and protect secrets needed to access your applications, services, and IT resources. It was detected that the secret {AwsSecretsManagerSecret}'s access policy grants public access. Public access may expose the secret to an unauthorized AWS accounts and users. Use the secret's access policy in order to restrict who can access it.