turbot/alicloud_compliance

Query: oss_bucket_encrypted_with_byok

Usage

powerpipe query alicloud_compliance.query.oss_bucket_encrypted_with_byok

SQL

select
'acs:oss:::' || b.name as resource,
case
when server_side_encryption ->> 'SSEAlgorithm' = 'KMS' and k.creator = k.account_id then 'ok'
else 'alarm'
end as status,
case
when server_side_encryption ->> 'SSEAlgorithm' = 'KMS' and k.creator = k.account_id then b.title || ' encrypted with BYOK.'
else b.title || ' not encrypted with BYOK.'
end as reason
, b.account_id as account_id, b.region as region
from
alicloud_oss_bucket b
left join alicloud_kms_key k on b.server_side_encryption ->> 'KMSMasterKeyID' = k.key_id;

Controls

The query is being used by the following controls: