IAM: ListServerCertificates - 'Verify certificate names and upload dates'

Information

Security measures that rely on encryption require keys. In the cloud, as in an on-premises system, it is essential to keep your keys secure. You can use existing processes to manage encryption keys in the cloud, or you can leverage server-side encryption with AWS key management and storage capabilities.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the names and upload dates of the server certificates.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: amazon_aws

Control ID: eae32d8f128ac81948a7e5d70871e0940de2cf6061e2041ba7554041a65700c5