Low
ACM
Regional
ACM certificates should be tagged
Description
Flags ACM certificates that have no user-defined tags. Tags help with ownership, cost allocation, and incident triage; certificates without any non-system tag are operationally opaque.
Remediation
Apply at least one user-defined tag to every ACM certificate.
Steps
- Open the AWS Certificate Manager console and select the certificate.
- On the certificate detail page, choose Tags and then Edit.
- Add at least one tag with a non-aws: prefixed key (e.g. Owner, Environment, CostCenter).
- Save the changes.