Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[datagov-brokerpak-solr] CloudWatch log group not encrypted with managed key #4105

Closed
2 tasks
nickumia-reisys opened this issue Dec 7, 2022 · 1 comment
Closed
2 tasks
Assignees
Labels
bug Software defect or bug compliance Relating to security compliance or documentation

Comments

@nickumia-reisys
Copy link
Contributor

nickumia-reisys commented Dec 7, 2022

Date of report: 12/06/2022
Severity: Low

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • CloudWatch log group not encrypted with managed key (Low)
    • Detailed paths
    • This issue is...
      • Log group is not encrypted with customer managed key
    • The impact of this is...
      • Scope of use of the key cannot be controlled via KMS/IAM policies
    • You can resolve it by...
      • Set kms_key_id attribute with customer managed key id
  • CloudWatch log group not encrypted with managed key (Low)
    • Detailed paths
    • This issue is...
      • Log group is not encrypted with customer managed key
    • The impact of this is...
      • Scope of use of the key cannot be controlled via KMS/IAM policies
    • You can resolve it by...
      • Set kms_key_id attribute with customer managed key id
@nickumia-reisys nickumia-reisys added compliance Relating to security compliance or documentation bug Software defect or bug labels Dec 7, 2022
@nickumia-reisys
Copy link
Contributor Author

@nickumia-reisys nickumia-reisys self-assigned this Oct 9, 2023
@nickumia-reisys nickumia-reisys moved this from ✔ Done to 🗄 Closed in data.gov team board Oct 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Software defect or bug compliance Relating to security compliance or documentation
Projects
Archived in project
Development

No branches or pull requests

1 participant