Medium
KMS
Regional
AWS KMS key rotation should be enabled
CISPCI DSSNIST
Description
Checks if AWS KMS keys have key rotation enabled. Key rotation helps manage the lifecycle of cryptographic material.
Remediation
To remediate KMS keys without rotation enabled, you need to enable rotation for each key.
Steps
- Open the AWS KMS console.
- Go to the 'Customer managed keys' section.
- Select the KMS key.
- Under 'Key rotation', select 'Enable' to activate key rotation.
Compliance
CISPCI DSSNIST