kmsKeyArn

The ARN of the Amazon Web Services KMS key that Security Hub uses to encrypt the export objects with server-side encryption. The key policy must allow the Security Hub service principal (exportv2.securityhub.amazonaws.com) to use the key through Amazon S3. For the required key policy, see the Examples section of StartExportJobV2.

The key must meet all of the following requirements:

  • It must be a symmetric key with a key usage of ENCRYPT_DECRYPT.

  • It must be a single-Region key. Multi-Region keys, whose key IDs begin with mrk-, are rejected.

  • You must specify the full key ARN. Key IDs and aliases are rejected.

  • The key must be in the same Amazon Web Services account as the export job.

  • The key must be in the same Amazon Web Services Region as the export job.

  • The key must be in the aws, aws-cn, or aws-us-gov partition.