More Info:

Ensure that a specific list of AWS KMS Customer Master Keys (CMKs) are available for use in your AWS account in order to meet strict security and compliance requirements in your organization.

Risk Level

Low

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

The misconfiguration of “Existence of specific AWS KMS CMKs” means that there are AWS KMS Customer Master Keys (CMKs) that should not exist in your AWS account. To remediate this issue, follow the below steps:

  1. Login to your AWS Management Console.
  2. Go to the AWS KMS console.
  3. Click on “Customer managed keys” in the left-hand navigation menu.
  4. Identify the CMKs that should not exist in your account.
  5. Select the CMKs that should not exist in your account.
  6. Click on the “Schedule key deletion” button.
  7. In the “Schedule key deletion” dialog box, specify the number of days after which the key will be deleted.
  8. Click on the “Schedule deletion” button.

Once the keys are scheduled for deletion, you can monitor the progress of the deletion process in the AWS KMS console. It is recommended to delete the CMKs that are no longer required to avoid any potential security risks.

Additional Reading: