More Info:

Any disabled KMS Customer Master Keys in your AWS account should be removed in order to lower the cost of your monthly AWS bill.

Risk Level

Medium

Address

Operational Maturity, Cost optimization, Security

Compliance Standards

NIST

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the issue of an unused Customer Master Key in AWS:

  1. Log in to the AWS Management Console.
  2. Go to the AWS Key Management Service (KMS) console.
  3. In the left navigation pane, select “Customer managed keys.”
  4. Find the Customer Master Key (CMK) that is not being used and select it.
  5. In the “Key state” section, check if the key is enabled or disabled. If the key is enabled, disable it by selecting “Disable key” from the “Actions” dropdown menu.
  6. Once the key is disabled, select “Schedule key deletion” from the “Actions” dropdown menu.
  7. In the “Schedule key deletion” dialog box, specify the number of days for which you want to retain the key before it is deleted permanently. You can select a minimum of 7 days and a maximum of 30 days.
  8. Click on the “Schedule key deletion” button to schedule the deletion of the key.

By following these steps, you can remediate the issue of an unused Customer Master Key in AWS and ensure that your cloud environment is secure.

Additional Reading: