Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Remediation Steps:

Perform following to assign root user of the account as owner of the key remove key administrator form user list :

  1. Login to the AWS Management Console at https://console.aws.amazon.com.

  2. Navigate to KMS console.

  3. Select the appropriate region from the top right corner.

  4. In the navigation pane, choose Customer managed keys, and then choose the CMK that you want to modify.

  5. Navigate to "Key policy" and click Switch to Policy View button. Click Edit.

  6. Add/modify the policy such that no principal with administrative privileges on the CMK is allowed user permissions on the CMK.

  7. Click Save changes.

...