More Info:

You should have KMS CMK customer-managed keys in use in your account instead of AWS managed-keys in order to have full control over your data encryption and decryption process.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the KMS Customer Master Key Should Be In Use misconfiguration in AWS using AWS console, follow these steps:

  1. Open the AWS Management Console and navigate to the AWS Key Management Service (KMS) console.

  2. Click on the “Customer managed keys” option in the left-hand menu.

  3. Identify the key that is not in use and select it by clicking on its alias.

  4. Click on the “Key actions” dropdown menu and select “Enable Key”.

  5. In the pop-up window, select the AWS service(s) that you want to use the key with and click “Enable”.

  6. Once enabled, the key will be available for use by the selected AWS service(s).

  7. Repeat steps 3-6 for any other keys that are not in use.

  8. Verify that the KMS Customer Master Key is now in use by checking the compliance status of the resource or by running a compliance check.

By following these steps, you can remediate the KMS Customer Master Key Should Be In Use misconfiguration in AWS using AWS console.

Additional Reading: