Review customer managed KMS key rotation

Use rotation supported by the key type and origin, and manage access permissions separately.

Description

KMS rotation reduces prolonged use of the same key material. Automatic rotation must be used with supported configurations, such as symmetric encryption keys generated by KMS. The key ARN and access policy remain unchanged; rotation alone neither re-encrypts existing data nor revokes a compromised principal’s permissions.

Potential impact

  • Missing required rotation can violate the organization’s key-material lifetime policy.
  • Treating rotation as revocation or data re-encryption can leave incident-response work incomplete.

Remediation

Check the key type and origin, and set enable_key_rotation = true where required for customer managed keys that support automatic rotation. Plan an appropriate replacement process for unsupported key types. Maintain key policies and a usage inventory, and revoke compromised permissions separately.

Examples

These examples compare automatic rotation for the default KMS-generated symmetric encryption key. Do not apply the setting indiscriminately to other key types.

Before

hcl
resource "aws_kms_key" "example" {
  description         = "KMS key 2"
  is_enabled          = true
  enable_key_rotation = false
}

After

hcl
resource "aws_kms_key" "example" {
  description         = "KMS key 1"
  is_enabled          = true
  enable_key_rotation = true
}

The revision enables automatic rotation. KMS retains older key material to decrypt data encrypted with it. The description-string change does not affect rotation.

References