Threagile / threagile

Agile Threat Modeling Toolkit
https://threagile.io
MIT License
577 stars 126 forks source link

Risk - Denial of Service by encrypting data in Cloud Storage and removing the key #29

Open BenjiTrapp opened 2 years ago

BenjiTrapp commented 2 years ago

Risk: All data within cloud storage might be encrypted and can lead to DoS by deleting the key

Remidiation: Increase deletion time of Keys (e.g. KMS) and bring up a watch of possibale deletion of keys. Create an alerting for non tagged ressources marked for deletion or stop the deletion process by use of AWS Config rules