Best Practices for Rotating an S3 Bucket Key
Beginning on May 15, 2025, Secure Access requires that an organization with a Cisco-managed S3 bucket rotate the IAM key credentials on their S3 bucket every 90 days.
- Rotating IAM keys every 90 days only applies to Cisco-managed S3 buckets not self-managed S3 buckets. If your organization is unable to rotate the IAM keys on their Cisco-managed S3 bucket, we recommend that the organization uses a self-managed Amazon S3 bucket.
- If the IAM keys on a Cisco-managed S3 bucket are not rotated within 90 days from when the keys were last rotated, the organization will lose access to the Cisco-managed S3 bucket.
Secure Access continues to log events to the Cisco-managed S3 bucket, but the S3 bucket is not accessible. - Secure Access provides periodic notifications about the expiry date of the IAM key on the Cisco-managed S3 bucket.