Medium
SecretsManager
Regional
Remove unused Secrets Manager secrets
NIST
Description
Flags secrets that have not been accessed within 90 days, indicating they may be stale or unused.
Remediation
To delete inactive Secrets Manager secrets, see Delete an AWS Secrets Manager secret in the AWS Secrets Manager User Guide.
Steps
- Go to the AWS Secrets Manager console.
- Identify secrets that have not been accessed within the specified period.
- Delete the unused secrets.
Compliance
NIST