Blocked KMS Actions In Inline Policies Should Be Set
More Info:
This rule checks if the inline policies attached to your IAM users do not allow blocked actions on all AWS Key Management Service (KMS) keys. The rule is NON_COMPLIANT if any blocked action is allowed on all AWS KMS keys in an inline policy.
Risk Level
Medium
Address
Security
Compliance Standards
- APRA CPS 234 (Australia)
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS Critical Security Controls v8
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- Cloudanix Best Practice
- DPDPA
- Digital Operational Resilience Act (EU)
- Essential 8
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Prevention
- Cause
- Remediation
How to Prevent
Using Console
To prevent blocked KMS actions in inline policies in IAM using the AWS Management Console, follow these steps:
-
Navigate to IAM Policies:
- Open the AWS Management Console.
- In the navigation pane, choose "Policies" under the "Access management" section.
-
Create or Edit a Policy:
- To create a new policy, click on the "Create policy" button.
- To edit an existing policy, find the policy you want to modify and click on its name, then click the "Edit policy" button.
-
Specify KMS Actions:
- In the policy editor, switch to the "JSON" tab.
- Ensure that the policy explicitly specifies the allowed KMS actions. For example:
{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": ["kms:Encrypt","kms:Decrypt","kms:GenerateDataKey"],"Resource": "*"}]}
-
Review and Save:
- After specifying the allowed KMS actions, click on the "Review policy" button.
- Provide a name and description for the policy if creating a new one.
- Click on the "Create policy" or "Save changes" button to apply the policy.
By following these steps, you ensure that the inline policies in IAM explicitly allow the necessary KMS actions, preventing any misconfigurations related to blocked KMS actions.
Using CLI
To prevent blocked KMS actions in inline policies in IAM using AWS CLI, you can follow these steps:
-
Create a JSON Policy Document:
- First, create a JSON file that defines the inline policy with the necessary permissions and explicitly denies the blocked KMS actions.
- Example JSON policy (
policy.json):{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": ["kms:Encrypt","kms:Decrypt","kms:GenerateDataKey"],"Resource": "*"},{"Effect": "Deny","Action": ["kms:DisableKey","kms:ScheduleKeyDeletion"],"Resource": "*"}]}
-
Attach the Inline Policy to an IAM User:
- Use the
put-user-policycommand to attach the inline policy to a specific IAM user. - Command:
aws iam put-user-policy --user-name <username> --policy-name <policy-name> --policy-document file://policy.json
- Use the
-
Attach the Inline Policy to an IAM Group:
- Use the
put-group-policycommand to attach the inline policy to a specific IAM group. - Command:
aws iam put-group-policy --group-name <groupname> --policy-name <policy-name> --policy-document file://policy.json
- Use the
-
Attach the Inline Policy to an IAM Role:
- Use the
put-role-policycommand to attach the inline policy to a specific IAM role. - Command:
aws iam put-role-policy --role-name <rolename> --policy-name <policy-name> --policy-document file://policy.json
- Use the
By following these steps, you can ensure that the necessary KMS actions are allowed while explicitly denying the blocked KMS actions in inline policies using AWS CLI.
Using Python
To prevent blocked KMS actions in inline policies in IAM using Python scripts, you can use the AWS SDK for Python (Boto3). Here are the steps to achieve this:
Step 1: Install Boto3
Ensure you have Boto3 installed in your Python environment. You can install it using pip if you haven't already:
pip install boto3
Step 2: Initialize Boto3 Client
Initialize the Boto3 client for IAM:
import boto3
iam_client = boto3.client('iam')
Step 3: Define the Inline Policy
Create a JSON structure for the inline policy that blocks specific KMS actions. For example, you can block the kms:Decrypt action:
inline_policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"kms:Decrypt"
],
"Resource": "*"
}
]
}
Step 4: Attach the Inline Policy to an IAM User or Role
Attach the inline policy to a specific IAM user or role. Here’s an example of attaching it to a user:
user_name = 'your-iam-user-name'
policy_name = 'BlockKMSActionsPolicy'
response = iam_client.put_user_policy(
UserName=user_name,
PolicyName=policy_name,
PolicyDocument=json.dumps(inline_policy)
)
print(f"Policy {policy_name} attached to user {user_name}")
Full Script Example
Here is the complete script combining all the steps:
import boto3
import json
# Initialize Boto3 client
iam_client = boto3.client('iam')
# Define the inline policy
inline_policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": [
"kms:Decrypt"
],
"Resource": "*"
}
]
}
# Attach the inline policy to an IAM user
user_name = 'your-iam-user-name'
policy_name = 'BlockKMSActionsPolicy'
response = iam_client.put_user_policy(
UserName=user_name,
PolicyName=policy_name,
PolicyDocument=json.dumps(inline_policy)
)
print(f"Policy {policy_name} attached to user {user_name}")
Summary
- Install Boto3: Ensure Boto3 is installed in your Python environment.
- Initialize Boto3 Client: Set up the IAM client using Boto3.
- Define the Inline Policy: Create a JSON structure for the inline policy to block specific KMS actions.
- Attach the Inline Policy: Use the
put_user_policymethod to attach the policy to an IAM user.
By following these steps, you can prevent blocked KMS actions in inline policies using Python scripts.
Check Cause
Using Console
-
Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/iam/.
-
In the navigation pane, choose "Policies". This will open a list of all the IAM policies that are currently configured in your AWS environment.
-
Select the policy you want to check for blocked KMS actions. This will open the policy details page.
-
In the policy details page, check the policy document for any "Deny" statements that are applied to KMS actions. If there are any "Deny" statements applied to KMS actions, then the policy is blocking those actions.
Using CLI
-
First, you need to install and configure AWS CLI on your local machine. You can do this by following the instructions provided by AWS. Make sure you have the necessary permissions to execute IAM related commands.
-
Once the AWS CLI is set up, you can list all the IAM policies using the following command:
aws iam list-policies --scope LocalThis command will return a list of all the IAM policies that are created within your AWS account.
-
For each policy, you can get the policy details including the policy document by using the following command:
aws iam get-policy-version --policy-arn <Policy_ARN> --version-id <Policy_Version_ID>Replace
<Policy_ARN>with the ARN of the policy and<Policy_Version_ID>with the version ID of the policy. This command will return the policy document which includes the permissions set by the policy. -
Now, you need to check the policy document for any blocked KMS actions. You can do this by looking for "kms:Deny" statements in the policy document. If you find any such statements, it means that some KMS actions are blocked in the inline policy. You can use a JSON parser or a script to automate this process. For example, in Python, you can use the
jsonmodule to parse the policy document and check for blocked KMS actions.
Using Python
-
Install and configure AWS SDK for Python (Boto3): You need to install and configure Boto3 to interact with AWS services. You can install it using pip:
pip install boto3Then, configure your AWS credentials either by setting the following environment variables:
AWS_ACCESS_KEY_ID = 'your_access_key'AWS_SECRET_ACCESS_KEY = 'your_secret_key'Or, you can create the credential file yourself at ~/.aws/credentials. At a minimum, it should look like this:
[default]aws_access_key_id = YOUR_ACCESS_KEYaws_secret_access_key = YOUR_SECRET_KEY -
Use Boto3 to list all IAM policies: You can use the
list_policiesmethod to retrieve all IAM policies. Here is a sample script:import boto3# Create IAM clientiam = boto3.client('iam')# List policiesresponse = iam.list_policies(Scope='All')for policy in response['Policies']:print(policy['PolicyName']) -
Get the policy details: For each policy, you can use the
get_policymethod to retrieve the policy details, including the policy document. Here is a sample script:import boto3# Create IAM clientiam = boto3.client('iam')# Get policyresponse = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')policy_document = response['Policy']['PolicyDocument']print(policy_document) -
Check for blocked KMS actions: You can parse the policy document to check if it contains any blocked KMS actions. Here is a sample script:
import boto3import json# Create IAM clientiam = boto3.client('iam')# Get policyresponse = iam.get_policy(PolicyArn='arn:aws:iam::aws:policy/AdministratorAccess')policy_document = response['Policy']['PolicyDocument']# Parse policy documentpolicy_document = json.loads(policy_document)# Check for blocked KMS actionsfor statement in policy_document['Statement']:if 'kms:Decrypt' in statement['Action'] and statement['Effect'] == 'Deny':print('Blocked KMS action found: kms:Decrypt')This script checks if the 'kms:Decrypt' action is blocked. You can modify it to check for other KMS actions.
Remediation
Using Console
To remediate the issue of blocked KMS actions in inline policies in AWS IAM using the AWS Management Console, follow these step-by-step instructions:
-
Sign in to the AWS Management Console:
- Navigate to the AWS Management Console (https://aws.amazon.com/console/) and sign in with your AWS account credentials.
-
Access the IAM service:
- In the AWS Management Console, search for "IAM" in the services search bar and click on the "IAM" service to access the IAM dashboard.
-
Identify the user/group/role with inline policy:
- Identify the user, group, or role that has an inline policy with blocked KMS actions. You can do this by navigating to the respective User, Group, or Role within the IAM dashboard.
-
Edit the inline policy:
- Select the user, group, or role that has the inline policy with blocked KMS actions.
- Under the "Permissions" tab, locate the inline policy that contains the blocked KMS actions.
- Click on the inline policy to edit it.
-
Update the inline policy:
- Within the inline policy editor, locate the section where KMS actions are defined.
- Remove any explicit deny statements that block KMS actions. Ensure that the necessary KMS actions are allowed as per your organization's policies.
-
Save the changes:
- After updating the inline policy to allow the required KMS actions, review the changes to ensure they are correct.
- Click on the "Save changes" or "Update policy" button to save the modified inline policy.
-
Verify the changes:
- Once the inline policy is updated, verify that the blocked KMS actions have been remediated.
- You can test the permissions by attempting to perform the KMS actions that were previously blocked.
-
Monitor for compliance:
- Regularly monitor your IAM policies and permissions to ensure that they comply with your organization's security and compliance requirements.
- Consider implementing AWS Config rules or AWS CloudTrail logs to track and alert on any future misconfigurations related to KMS actions.
By following these steps, you can successfully remediate the issue of blocked KMS actions in inline policies within AWS IAM using the AWS Management Console.
Using CLI
To remediate the misconfiguration of blocked KMS actions in inline policies in AWS IAM using AWS CLI, follow these steps:
Step 1: Identify the IAM user or role with the inline policy containing blocked KMS actions.
Step 2: Use the AWS CLI to view the inline policy attached to the IAM user or role. Replace IAM-ENTITY-NAME with the actual IAM user or role name.
aws iam list-user-policies --user-name IAM-ENTITY-NAME
or
aws iam list-role-policies --role-name IAM-ENTITY-NAME
Step 3: Get the policy document for the inline policy. Replace IAM-ENTITY-NAME with the actual IAM user or role name and POLICY-NAME with the policy name.
aws iam get-user-policy --user-name IAM-ENTITY-NAME --policy-name POLICY-NAME
or
aws iam get-role-policy --role-name IAM-ENTITY-NAME --policy-name POLICY-NAME
Step 4: Review the policy document to identify the blocked KMS actions.
Step 5: Modify the policy document to allow the required KMS actions. You can create a new policy or update the existing policy based on your requirements.
Step 6: Update the inline policy for the IAM user or role with the modified policy document. Replace IAM-ENTITY-NAME, POLICY-NAME, and POLICY-DOCUMENT with the actual values.
aws iam put-user-policy --user-name IAM-ENTITY-NAME --policy-name POLICY-NAME --policy-document file://POLICY-DOCUMENT.json
or
aws iam put-role-policy --role-name IAM-ENTITY-NAME --policy-name POLICY-NAME --policy-document file://POLICY-DOCUMENT.json
Step 7: Verify that the inline policy has been updated successfully by checking the policy document.
By following these steps, you can remediate the misconfiguration of blocked KMS actions in inline policies in AWS IAM using AWS CLI.
Using Python
To remediate the issue of blocked KMS actions in inline policies for AWS IAM using Python, you can follow these steps:
- Identify the IAM user or role with the inline policy that contains blocked KMS actions.
- Update the inline policy to allow the necessary KMS actions.
- Use the AWS SDK for Python (Boto3) to programmatically update the inline policy.
Here is a sample Python script to remediate this issue:
import boto3
iam = boto3.client('iam')
# IAM user or role name with the inline policy containing blocked KMS actions
entity_name = 'YOUR_IAM_ENTITY_NAME'
policy_name = 'YOUR_POLICY_NAME'
# Define the necessary KMS actions to be allowed in the policy
kms_actions = [
"kms:Encrypt",
"kms:Decrypt",
# Add more KMS actions as needed
]
# Get the current policy document
response = iam.get_user_policy(UserName=entity_name, PolicyName=policy_name)
policy_document = response['PolicyDocument']
# Update the policy document to allow the KMS actions
for statement in policy_document['Statement']:
if 'Resource' in statement and statement['Resource'].startswith('arn:aws:kms'):
if 'Effect' in statement and statement['Effect'] == 'Deny':
statement['Effect'] = 'Allow'
statement['Action'] = kms_actions
# Update the policy with the modified document
iam.put_user_policy(UserName=entity_name, PolicyName=policy_name, PolicyDocument=policy_document)
print(f"Updated inline policy {policy_name} for {entity_name} to allow KMS actions: {kms_actions}")
Make sure to replace YOUR_IAM_ENTITY_NAME and YOUR_POLICY_NAME with the appropriate values for your IAM user or role and policy name.
After running this script, the inline policy for the specified IAM user or role should be updated to allow the necessary KMS actions, remedying the misconfiguration.
Using Terraform
resource "aws_iam_user" "example" {
name = "EXISTING_USER_NAME" # replace with your IAM user name
}
resource "aws_iam_user_policy" "kms_restricted" {
name = "EXISTING_INLINE_POLICY_NAME" # replace with the inline policy name on the user
user = aws_iam_user.example.name
# Replace the JSON below with your existing policy document,
# but ensure any KMS statements do NOT use "Resource": "*"
policy = jsonencode({
Version = "2012-10-17"
Statement = [
# Example of a previously over‑permissive statement:
# {
# "Effect": "Allow",
# "Action": [
# "kms:Encrypt",
# "kms:Decrypt",
# "kms:GenerateDataKey*"
# ],
# "Resource": "*"
# }
# Corrected: restrict KMS actions to specific key ARNs (NO "*")
{
Effect = "Allow"
Action = [
"kms:Encrypt",
"kms:Decrypt",
"kms:GenerateDataKey*",
]
Resource = [
"arn:aws:kms:AWS_REGION:AWS_ACCOUNT_ID:key/KMS_KEY_ID_1",
"arn:aws:kms:AWS_REGION:AWS_ACCOUNT_ID:key/KMS_KEY_ID_2",
]
}
# …include any other non‑KMS statements from your existing policy unchanged…
]
})
}
This change updates the inline user policy in place (no resource replacement, but permissions may change and affect workloads).
For verification, terraform plan should show an in-place update of aws_iam_user_policy.kms_restricted where only the policy JSON changes from Resource: "*" to the specific KMS key ARNs.