This product is not supported for your selected
Datadog site. (
).
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Id: 7350fa23-dcf7-4938-916d-6a60b0c73b50
Cloud Provider: aws
Framework: Terraform
Severity: Medium
Category: Availability
Learn More
Description
This check ensures that AWS Key Management Service (KMS) Customer Master Keys (CMKs) are configured with the is_enabled
attribute set to TRUE
, making them usable for cryptographic operations such as encryption and decryption. If this attribute is set to FALSE
, the CMK becomes unusable, preventing applications and services from accessing encrypted data or generating new data keys. Leaving CMKs disabled can disrupt access to critical resources and services, potentially resulting in application outages, data unavailability, or failed backup and restore operations. Properly enabling CMKs is crucial to maintaining secure and continuous access to resources that depend on AWS KMS.
Compliant Code Examples
resource "aws_kms_key" "a3" {
description = "KMS key 1"
is_enabled = true
}
Non-Compliant Code Examples
resource "aws_kms_key" "a" {
description = "KMS key 1"
is_enabled = false
}