Glossary

    Key Rotation

    Data Protection

    Key Rotation is the practice of periodically replacing cryptographic keys with new key material. This limits the amount of data encrypted under any single key and reduces the impact if a key is compromised.

    AWS KMS Key Rotation

    • Automatic rotation generates new key material on a configurable schedule (default: annually, range: 90 days to 7 years)
    • The key ID and ARN stay the same - no application changes needed
    • Old key material is preserved so previously encrypted data can still be decrypted
    • On-demand rotation also available (rotate immediately)

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.