More Info:

Ensure that all KMS keys are configured to be accessed only by trusted accounts in order to prevent unauthorized access

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the KMS Cross Account Access misconfiguration in GCP using the GCP console, follow these steps:

  1. Open the GCP Console and navigate to the Key Management Service (KMS) page.
  2. Select the key ring that has cross-account access enabled.
  3. Click on the key for which cross-account access is enabled.
  4. Click on the “Permissions” tab.
  5. Click the “Edit” button at the top of the page.
  6. Find the member that has cross-account access and click the “X” to remove it.
  7. Click “Save” to save the changes.

Once you have completed these steps, cross-account access will be disabled for the selected key. Ensure that you have reviewed all the other keys and key rings and disabled cross-account access for any other keys that may have it enabled.