1 Risposta
- Più recenti
- Maggior numero di voti
- Maggior numero di commenti
1
Hello,
-
After a KMS key is deleted, you can no longer decrypt the data that was encrypted under that KMS key, which means that data becomes unrecoverable.
-
You should delete a KMS key only when you are sure that you don't need to use it anymore. If you are not sure, consider disabling the KMS key instead of deleting it. You can re-enable a disabled KMS key and cancel the scheduled deletion of a KMS key, but you cannot recover a deleted KMS key.
-
Restrict the key deletion access through IAM policies.
refer to below documentation regarding scheduling & deleting customer managed key.
con risposta 2 anni fa
Contenuto pertinente
- AWS UFFICIALEAggiornata un anno fa

thanks .. I know, my question was how we can restrict deleting the key?