Skip to content

Commit ff0de4c

Browse files
authored
Update concept-data-security-posture-prepare.md
KMS key clarifications
1 parent 3cdffdc commit ff0de4c

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

articles/defender-for-cloud/concept-data-security-posture-prepare.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,8 +91,9 @@ To protect AWS resources in Defender for Cloud, set up an AWS connector using a
9191
- Delete/update DB/cluster snapshot with prefix *defenderfordatabases*
9292
- List all KMS keys
9393
- Use all KMS keys only for RDS on source account
94-
- Full control on all KMS keys with tag prefix *DefenderForDatabases*
94+
- Create & full control on all KMS keys with tag prefix *DefenderForDatabases*
9595
- Create alias for KMS keys
96+
- KMS keys are created once for each region that contains RDS instances. The creation of a KMS key may incur a minimal additional cost, according to AWS KMS pricing.
9697

9798
### Discovering GCP storage buckets
9899

0 commit comments

Comments
 (0)