IAM misconfigurations

Over privileged KMS user

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

A user/service account with overly permissive KMS related roles was found. It is recommended that the principle of 'Separation of Duties' is enforced while assigning KMS related roles to users. No user should have Cloud KMS Admin and any of the Cloud KMS CryptoKey Encrypter/Decrypter, Cloud KMS CryptoKey Encrypter, Cloud KMS CryptoKey Decrypter roles assigned at the same time.
  • Recommended Mitigation

    For any member (service account or user) having Cloud KMS Admin and any of the Cloud KMS CryptoKey Encrypter/Decrypter, Cloud KMS CryptoKey Encrypter, Cloud KMS CryptoKey Decrypter roles granted/assigned, remove all unnecessary permissions.