AWS Secrets Manager
Connect AWS Secrets Manager to Iru Compliance Automation to collect secret inventory, rotation schedules, and tags.
Rotation is supposed to be the control on stored secrets — Iru connects to AWS Secrets Manager and reads rotation status, resource policies, and access logs directly, so rotation is proven instead of assumed.
Key Capabilities
- Verify secrets rotate automatically on a defined schedule
- Confirm no secret has gone unrotated beyond policy
- Show that secret access follows least privilege
Evidence Collected
- Secret inventory with rotation schedules
- Rotation status against policy
- Resource policies showing least privilege access
- CloudTrail audit logs of secret access
- Rotation Lambda health and execution logs