27 of 29 in All Controls
aws

Enforce Customer Managed KMS Keys and Key Rotation for Audit Logs

IDAWS-LOG-003
Severity
high
Automation
Auto
Category
logging
Enforcementmandatory
Complexity / Impact
medium(none impact)
Cloud Scopeaws:account
Environments
all
Target Resources
AWS::KMS::KeyAWS::CloudTrail::TrailAWS::S3::Bucket
Services
kmscloudtrails3iam
Tags
loggingencryptionkmscmkkey-rotationlanding-zonesecurity
Frameworks
CIS AWSNIST SP 800-53 Rev 5ISO/IEC 27001:2022SOC 2PCI DSSHIPAA Security Rule
Governance
Cloud Security (quarterly)
Audit Dates
2026-05-03 • 2026-08-21

Specification & Description

Enforce the use of Customer Managed Keys (CMKs) with automated key rotation enabled and strict cross-account key policies for encrypting centralized CloudTrail and audit log archives.

Technical Specifications

Default AWS-managed keys (aws/s3 or aws/cloudtrail) are insufficient for enterprise Landing Zone audit logging because their key policies cannot be modified to restrict access, cannot be shared across accounts with granular IAM conditions, and do not provide detailed KMS access logs for forensic investigation.

1. Customer Managed Key (CMK) Governance

  • All audit trails and centralized log archive buckets must use dedicated AWS KMS Customer Managed Keys.
  • CMKs provide granular control over key administration versus key usage permissions.
  • Decryption capabilities can be isolated to dedicated security and forensic roles, preventing unauthorized member account admins from decrypting sensitive organizational audit trails.

2. Automated Key Rotation

  • Regular automated key rotation must be enabled on the KMS key.
  • When rotation occurs, KMS automatically creates a new backing key while retaining previous versions to seamlessly decrypt historical logs without manual key migration.

3. Multi-Account KMS Key Policy Guardrails

  • Key policies must explicitly allow the cloudtrail.amazonaws.com service principal to generate data keys across the organization using aws:SourceOrgID conditions.
  • Key policies must prevent kms:DisableKey, kms:ScheduleKeyDeletion, or policy modifications by unauthorized principals.

Security Rationale

Using KMS Customer Managed Keys with automated rotation ensures cryptographic separation of duties and maintains log confidentiality. Even if an attacker compromises an S3 bucket policy or acquires raw S3 object permissions, they cannot decrypt the forensic logs without explicit KMS key permissions. Automated key rotation limits the cryptanalytic blast radius of any individual key version.

We value your privacy

We use analytics cookies to understand how visitors interact with our site and to improve the user experience. You can choose to accept or decline these cookies.