More Info:

Delete any disabled KMS Customer Master Keys (CMKs) and remove them in order to lower costs.

Risk Level

Low

Address

Reliability, Security

Compliance Standards

NIST

Triage and Remediation

Remediation

To remediate the misconfiguration “Customer Master Keys (CMKs) Should Be Used” for GCP using GCP console, follow the below steps:

  1. Log in to the Google Cloud Console.
  2. Navigate to the Cloud KMS page.
  3. Click on “Create Key Ring” to create a new key ring.
  4. Enter a name for the key ring and select the location where you want to create the key ring.
  5. Click on “Create”.
  6. Navigate to the “Create Key” page.
  7. Select the key ring that you created in step 4.
  8. Enter a name for the key and select the key version.
  9. Select the key algorithm and protection level.
  10. Click on “Create”.
  11. Navigate to the “IAM” page.
  12. Click on “Add Member” to add a new member to the project.
  13. Enter the email address of the member and select the role that you want to assign to the member.
  14. Click on “Save”.

By following these steps, you have now created a new key ring, created a new key, and assigned a role to a member. You can now use this key to encrypt and decrypt data in GCP.