More Info:

Ensure that a specific list of KMS CMKs are available for use in your AWS account in order to meet the security and compliance requirements of the organization.

Risk Level

Low

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of checking for the existence of specific KMS CMKs in GCP using GCP console, follow these steps:

  1. Open the Google Cloud Console and select the project that you want to work on.

  2. In the navigation menu, select “Security” and then select “Security Health Analytics”.

  3. Under “Security Health Analytics”, select “Findings”.

  4. In the search bar, enter “KMS” and select “KMS Key Ring Has No Rotation Policy”.

  5. This will show you a list of all the KMS key rings that have no rotation policy.

  6. For each key ring that has no rotation policy, click on the key ring name to open it.

  7. In the key ring page, click on the “Edit” button.

  8. Under “Rotation Interval”, select the desired rotation interval from the drop-down menu.

  9. Click on “Save” to save the changes.

  10. Repeat steps 6-9 for all the key rings that have no rotation policy.

By following these steps, you will remediate the misconfiguration of checking for the existence of specific KMS CMKs in GCP using GCP console.