Secrets Manager secret has not been accessed in over 90 days
- Severity
- Low
- Service
- Secrets Manager
- Check ID
- SECRETSMANAGER_SECRET_UNUSED
What this check finds
A secret that has never been accessed or has not been accessed for more than 90 days may be orphaned. Unused secrets still incur a cost of $0.40/month each, and a large number of stale secrets increases the blast radius if the Secrets Manager API is compromised.
Passing looks like: No unused Secrets Manager secrets.
How to fix it
Confirm whether the secret is still in use. If not, delete it: aws secretsmanager delete-secret --secret-id SECRET_NAME --recovery-window-in-days 7.
AWS console
Secrets Manager → Secrets → select secret → Delete secret.
Compliance
This is an operational hygiene check. It flags something worth tidying rather than a control an auditor asks for, so it is not mapped to a compliance framework.
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs