KMS automatic key rotation needs review

Check that automatic rotation for supported KMS keys meets your key-management policy.

Description

A KMS key with automatic rotation disabled does not generate new key material on a schedule. Automatic rotation is supported for symmetric encryption keys with AWS KMS-generated material; configure it according to the key type and your rotation policy.

Rotation preserves the key ID and permissions and does not re-encrypt existing data. It does not replace revoking compromised access or replacing exposed data keys.

Potential impact

  • A required rotation schedule may not be met.
  • Treating rotation as incident remediation can leave excessive key permissions or exposed data unaddressed.

Remediation

  • Set EnableKeyRotation: true for supported keys and apply the required rotation period.
  • For keys without automatic rotation support, plan another supported rotation procedure while retaining necessary decryption access.
  • Verify rotation status and history, and manage key permissions and incident response separately.

Examples

The examples use a symmetric encryption key with AWS KMS-generated material. Replace the account ARN with the actual administrative account and review the key policy.

Before

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  myKey:
    Type: AWS::KMS::Key
    Properties:
      Description: An example symmetric CMK
      EnableKeyRotation: false
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: Enable IAM User Permissions
            Effect: Allow
            Principal:
              AWS: arn:aws:iam::111122223333:root
            Action: kms:*
            Resource: "*"

Automatic rotation is disabled. Check manual or on-demand rotation separately.

After

yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
  myKey:
    Type: AWS::KMS::Key
    Properties:
      Description: An example symmetric CMK
      EnableKeyRotation: true
      KeyPolicy:
        Version: "2012-10-17"
        Id: key-default-1
        Statement:
          - Sid: Enable IAM User Permissions
            Effect: Allow
            Principal:
              AWS: arn:aws:iam::111122223333:root
            Action: kms:*
            Resource: "*"

Automatic rotation is enabled. Existing ciphertext remains decryptable with its corresponding key material, and access permissions do not change.

References