Skip to content

[Compliance] FAIL — All KMS key rotation periods are 90 days or less #16

@github-actions

Description

@github-actions

Compliance gap detected

Field Value
Signal all_kms_keys_rotate_within_90d
Evidence gcp_encryption
GCP project project-2b1e7276-412a-4f3c-9d6
Detected 2026-03-23
PCI-DSS 3.7.1
SOC 2 CC6.7
ISO 27001 A.8.24
ISO 42001

Affected resources

Resource Detail Remediation
demo-key-no-rotation Enable automatic rotation in Cloud KMS > Key rings.
demo-weak-tls-policy Update the SSL policy to set minTlsVersion to TLS_1_2 or higher.

Next steps

  1. Review the evidence artifact in evidence/gcp_encryption/latest.json
  2. Remediate the finding in GCP or Google Workspace
  3. Re-run the collector workflow to verify
  4. Close this issue once the signal shows PASS

Opened automatically by the compliance workflow · Run 23445929524

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions