SEC09-BP01 Implement secure key and certificate management
Use AWS Certificate Manager and Private CA to issue, deploy and rotate TLS certificates, avoiding manual installation and unmanaged certificate stores.
4
artefacts
2
held by a system
0
at each review
easy
to go live
Key management / PKI
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Certificate expiry monitoring · Key management / PKI
- Renewal automation logs · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- ACM certificate inventory · Policy repository / GRC workspace
- Private CA hierarchy · Document repository
First move
Automate the pull from your Key management / PKI. Key inventory, rotation dates and certificate expiry from the KMS or PKI.
Common gaps auditors find
- self signed certs in production
- expired certificates
- manual installation
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSEC08-BP04 Enforce access control · SEC09-BP02 Enforce encryption in transit