More Info:

Any disabled AWS KMS Customer Master Keys (CMK) that have been accidentally or intentionally scheduled for deletion should be recovered in order to prevent losing any data encrypted with these keys.

Risk Level

Low

Address

Reliability, Security

Compliance Standards

HIPAA, NIST, AWSWAF

Triage and Remediation

Remediation

Sure, here are the step by step instructions to remediate the KMS Keys Scheduled for Deletion should be recovered misconfiguration in AWS using the AWS console:

  1. Open the AWS Management Console and navigate to the KMS service.

  2. In the left navigation pane, click on “Scheduled Deletion”.

  3. Check the list of keys scheduled for deletion and identify the key that needs to be recovered.

  4. Select the key by clicking on the checkbox next to it.

  5. Click on the “Recover” button on the top of the page.

  6. In the confirmation dialog box, click on the “Recover” button again to confirm the recovery.

  7. Once the key is recovered, it will be available for use again.

That’s it! You have successfully remediated the KMS Keys Scheduled for Deletion should be recovered misconfiguration in AWS using the AWS console.

Additional Reading: