<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Kms on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/kms/</link><description>Recent content in Kms on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 02 Jun 2026 19:01:54 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/kms/index.xml" rel="self" type="application/rss+xml"/><item><title>Manage Unused AWS KMS Keys &amp; Prevent Deletions</title><link>https://zxcloudsecurity.co.uk/posts/aws-kms-unused-keys-prevent-accidental-deletion/</link><pubDate>Tue, 02 Jun 2026 19:01:54 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-kms-unused-keys-prevent-accidental-deletion/</guid><description>Learn how to audit unused AWS KMS keys, reduce costs, meet compliance requirements, and prevent accidental key deletions across multi-account environments.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/blogs/security/identify-unused-aws-kms-keys-and-prevent-accidental-key-deletions/">AWS Security Blog</a></p>
<hr>
<p>AWS has published guidance on identifying unused KMS encryption keys and protecting them from accidental deletion across large, multi-account environments. Orphaned or forgotten keys can inflate costs, create compliance gaps, and pose a risk if unexpectedly deleted — potentially making encrypted data permanently inaccessible. The post outlines tooling and processes to audit key usage and apply deletion safeguards at scale.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Implement regular KMS key usage audits using AWS CloudTrail and CloudWatch metrics, and ensure deletion windows and key policies are configured to prevent accidental removal — particularly in multi-account organisations where key ownership can become unclear over time.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/blogs/security/identify-unused-aws-kms-keys-and-prevent-accidental-key-deletions/">Identify unused AWS KMS keys and prevent accidental key deletions</a></p>
]]></content:encoded></item></channel></rss>