KMS customer managed key automatic rotation disabled

Rotate key material for supported KMS keys according to policy.

Description

KMS automatic rotation periodically replaces the key material of supported customer managed keys. Previous key material is retained for decryption; stored data is not automatically re-encrypted.

Potential impact

Without a rotation process, an organization may fail to meet its key-rotation schedule or audit requirements.

Remediation

Set EnableKeyRotation: true where required for symmetric encryption keys with AWS KMS-generated key material. Establish an appropriate manual replacement process for key types that do not support automatic rotation.

Examples

The examples enable automatic rotation on a default symmetric encryption key. Rotation does not replace revoking compromised access permissions.

Before

yaml
Resources:
  MyKey:
    Type: AWS::KMS::Key
    Properties:
      Enabled: true
      EnableKeyRotation: false

After

yaml
Resources:
  MyKey:
    Type: AWS::KMS::Key
    Properties:
      Enabled: true
      EnableKeyRotation: true

References