To ensure a secret version isn't immediately destroyed upon request, you can configure a delayed destruction policy for your Secret Manager secrets. This allows the secret to remain recoverable for a specified period. When a destruction delay is set, destroying a secret version will disable it immediately and schedule its final destruction after the configured duration has passed.
This rule resolution is part of the Conformity Security & Compliance tool for GCP.
Any user with administrative permissions can destroy a Secret Manager secret version. As this is an irreversible action, configuring a delayed destruction policy is strongly recommended to prevent immediate and accidental destruction of sensitive data. Setting a delayed destruction duration represents an extra layer of protection against accidental or malicious destruction of critical secret material.
Audit
To determine if a delayed destruction policy is configured for your Secret Manager secrets, perform the following operations:
Remediation / Resolution
To ensure that a delayed destruction policy is configured for your Google Cloud Secret Manager secrets, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- List secrets and view secret details
- Delay destruction of secret versions
- Destroy a secret version
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud secrets list
- gcloud secrets describe
- gcloud secrets update