create-key
command:
schedule-key-deletion
command:
get-key-rotation-status
command:
enable-key-rotation
command:
update-trail
command to enable logging for a specific trail:
<old-key-id>
, <key-id>
, and <trail-name>
with the appropriate values specific to your environment.
boto3
library to create a new CloudTrail trail for KMS.kms.amazonaws.com
as the resource type.boto3
library to create a new AWS Config rule for KMS.boto3
library to enable AWS Security Hub for KMS.