Google Cloud KMS
Connect Google Cloud KMS to Iru Compliance Automation to collect key rings, IAM bindings, and crypto API logs.
Iru connects to Google Cloud KMS to track your encryption key lifecycle and every cryptographic operation performed against it, with who or what triggered it. It reads key inventories, IAM bindings, and Cloud Audit Logs directly.
Key Capabilities
- Confirm encryption keys are governed with defined rotation
- Verify key operations are attributable to an actor and outcome
- Show that access to sensitive decrypt paths is justified where advanced controls are on
Evidence Collected
- Key ring and key inventory with rotation settings
- IAM bindings on keys
- Cloud Audit Logs capturing KMS and crypto API calls with actor, resource, and outcome
- Key Access Justifications where enabled