Risk Level: Critical
Cloud Entity: AWS Key Management Service (KMS)
CloudGuard Rule ID: D9.AWS.DR.06
Covered by Spectral: No
Category: Security, Identity, & Compliance
KMS where keyState='PendingDeletion' should have keyState='Disabled'
- Sign in to the AWS Management Console.
- Navigate to KMS dashboard.
- In the left navigation panel, click Customer Managed Keys.
- Select the appropriate AWS region from the Filter menu.
- Under Status column: check for any keys scheduled for deletion. If the current status is Pending Deletion, the key is scheduled for deletion.
- Under status column press 'Cancel Key Deletion' in order to cancel key deletion.
- Repeat step no. 5 and 6 for all AWS regions.
From Command Line
aws kms cancel-key-deletion --key-id KEYID
AWS Key Management Service (KMS) is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data, and uses FIPS 140-2 validated hardware security modules to protect the security of your keys. AWS Key Management Service is integrated with most other AWS services to help you protect the data you store with these services. AWS Key Management Service is also integrated with AWS CloudTrail to provide you with logs of all key usage to help meet your regulatory and compliance needs.
- CloudGuard AWS All Rules Ruleset
Updated 3 months ago