kmsKeyArn
The ARN of the Amazon Web Services KMS key that Security Hub uses to encrypt the export objects with server-side encryption. The key policy must allow the Security Hub service principal (exportv2.securityhub.amazonaws.com) to use the key through Amazon S3. For the required key policy, see the Examples section of StartExportJobV2.
The key must meet all of the following requirements:
It must be a symmetric key with a key usage of
ENCRYPT_DECRYPT.It must be a single-Region key. Multi-Region keys, whose key IDs begin with
mrk-, are rejected.You must specify the full key ARN. Key IDs and aliases are rejected.
The key must be in the same Amazon Web Services account as the export job.
The key must be in the same Amazon Web Services Region as the export job.
The key must be in the
aws,aws-cn, oraws-us-govpartition.