Description
KMS automatic rotation periodically replaces the key material of supported customer managed keys. Previous key material is retained for decryption; stored data is not automatically re-encrypted.
Potential impact
Without a rotation process, an organization may fail to meet its key-rotation schedule or audit requirements.
Remediation
Set EnableKeyRotation: true where required for symmetric encryption keys with AWS KMS-generated key material. Establish an appropriate manual replacement process for key types that do not support automatic rotation.
Examples
The examples enable automatic rotation on a default symmetric encryption key. Rotation does not replace revoking compromised access permissions.
Before
yaml
Resources:
MyKey:
Type: AWS::KMS::Key
Properties:
Enabled: true
EnableKeyRotation: false
After
yaml
Resources:
MyKey:
Type: AWS::KMS::Key
Properties:
Enabled: true
EnableKeyRotation: true