Control: KMS keys should not be pending deletion
Description
To help protect data at rest, ensure necessary customer master keys (CMKs) are not scheduled for deletion in AWS Key Management Service (AWS KMS).
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.kms_key_not_pending_deletion
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.kms_key_not_pending_deletion --share
SQL
This control uses a named query:
kms_key_not_pending_deletion