Secrets Manager secret has not been accessed in over 90 days

Severity
Low
Service
Secrets Manager
Check ID
SECRETSMANAGER_SECRET_UNUSED

What this check finds

A secret that has never been accessed or has not been accessed for more than 90 days may be orphaned. Unused secrets still incur a cost of $0.40/month each, and a large number of stale secrets increases the blast radius if the Secrets Manager API is compromised.

Passing looks like: No unused Secrets Manager secrets.

How to fix it

Confirm whether the secret is still in use. If not, delete it: aws secretsmanager delete-secret --secret-id SECRET_NAME --recovery-window-in-days 7.

AWS console

Secrets Manager → Secrets → select secret → Delete secret.

Compliance

This is an operational hygiene check. It flags something worth tidying rather than a control an auditor asks for, so it is not mapped to a compliance framework.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More Secrets Manager checks

All Secrets Manager checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only