Ensure that a specific list of AWS KMS Customer Master Keys (CMKs) are available for use in your AWS account in order to meet strict security and compliance requirements in your organization. Before this rule runs, the list of specific KMS Customer Master Keys must be defined in the rule settings, on the TrendAI Vision One™ Cloud Risk Management Dashboard dashboard.
This rule can help you with the following compliance standards:
- NIST4
For further details on compliance standards supported by TrendAI Vision One™ Cloud Risk Management, see here.
This rule can help you work with the AWS Well-Architected Framework.
Using the specified set of Amazon KMS Customer Master Keys (CMKs) to encrypt data within your AWS account can provide a better control over encryption/decryption process and fulfill compliance requirements when it comes to data protection in your organization.
Audit
To determine if the KMS keys specified in the rule settings (e.g. "highlyprotected", "protected", "internal", etc) are available for use in your AWS account, perform the following actions:
Remediation / Resolution
To create the required Amazon KMS Customer Master Keys (CMKs), defined in the rule settings, perform the following actions:
References
- AWS Documentation
- AWS Key Management Service FAQs
- What is AWS Key Management Service?
- AWS Key Management Service Concepts
- Viewing Keys
- Creating Keys
- AWS Command Line Interface (CLI) Documentation
- kms
- list-aliases
- create-key
- create-alias