Medium
KMS
IAM customer managed policies should not allow decryption actions on all KMS keys
NISTISO 27001HIPAA
Description
Checks whether IAM customer managed policies allow decryption actions on all KMS keys, which could lead to unauthorized decryption of sensitive data.
Remediation
To ensure IAM policies do not allow decryption actions on all KMS keys, modify the policies to restrict 'kms:Decrypt' to specific resources or remove it from the policy.
Steps
- Log in to the AWS Management Console.
- Navigate to the IAM service.
- In the navigation pane, click on 'Policies'.
- Search for and select the customer managed policy to modify.
- Click on the policy to open its details page.
- On the policy details page, click on 'Edit policy'.
- Modify the policy statements to restrict 'kms:Decrypt' to specific resources, or remove the action if it's not needed.
- Review the policy changes, then click 'Review policy' and 'Save changes'.
Compliance
NISTISO 27001HIPAA