- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
AWS Key Management Service (KMS) allows customers to rotate the backing key, which is the key material stored within the KMS. The backing key is tied to the key ID of the Customer Created customer master key (CMK). The backing key is used to perform cryptographic operations such as encryption and decryption. Automated key rotation retains all prior backing keys so that decryption of encrypted data can take place transparently. Datadog recommends enabling CMK key rotation for symmetric keys. Key rotation can not be enabled for any asymmetric CMK.
Rotating encryption keys helps reduce the potential impact of a compromised key as data encrypted with a new key cannot be accessed with a previous key that may have been exposed. Keys should be rotated every year, or upon an event that would result in the compromise of that key.
Creation, management, and storage of CMKs may require additional time from an administrator.
Run the following command to enable key rotation:
aws kms enable-key-rotation --key-id <kms_key_id>