Resource Type: AWS > KMS > Key
Resource Context
Key is a part of the KMS service.
Each Key lives under a Region.
Controls
The primary controls for AWS > KMS > Key are:
It is also targeted by these controls:
- AWS > CIS v1 > 2 Logging > 2.08 Ensure rotation for customer created CMKs is enabled (Scored)
- AWS > CIS v1.4 > 3 - Logging > 3.08 - Ensure rotation for customer created CMKs is enabled (Automated)
- AWS > CIS v2.0 > 3 - Logging > 3.08 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS > CIS v3.0 > 3 - Logging > 3.06 - Ensure rotation for customer created symmetric CMKs is enabled
- AWS > HIPAA > KMS > KMS CMK rotation should be enabled
- AWS > HIPAA > KMS > KMS keys should not be pending deletion
- AWS > NIST 800-53 > KMS > KMS CMK rotation should be enabled
- AWS > NIST 800-53 > KMS > KMS keys should not be pending deletion
- AWS > PCI v3.2.1 > KMS > 1 Customer master key (CMK) rotation should be enabled
Quick Actions
- Delete from AWS
- Set Tags
- Skip alarm for Active control
- Skip alarm for Active control [90 days]
- Skip alarm for Approved control
- Skip alarm for Approved control [90 days]
- Skip alarm for Tags control
- Skip alarm for Tags control [90 days]
Category
In Your Workspace
- Controls by Resource Type report
- Policy Settings by Resource Type report
- Resources by Resource Type report
Developers
- tmod:@turbot/aws-kms#/resource/types/key
- tmod:@turbot/turbot#/resource/categories/security
- turbot graphql resource --id "tmod:@turbot/aws-kms#/resource/types/key"
Get Resource- select * from guardrails_resource where resource_type_uri = 'tmod:@turbot/aws-kms#/resource/types/key';
- select * from guardrails_policy_setting where filter = 'resourceTypeId:"tmod:@turbot/aws-kms#/resource/types/key"';
- select * from guardrails_notification where resource_type_uri = 'tmod:@turbot/aws-kms#/resource/types/key' and notification_type in ('resource_updated', 'resource_created');
Get ResourceGet Policy Settings (By Resource ID)Get Resource Notification
Resource Type URI
Category URI
GraphQL
CLI
Steampipe Query