Software Secure Access
Activity Manage

Best Practices for Rotating an S3 Bucket Key

Beginning on May 15, 2025, Secure Access requires that an organization with a Cisco-managed S3 bucket rotate the IAM key credentials on their S3 bucket every 90 days.

  • Rotating IAM keys every 90 days only applies to Cisco-managed S3 buckets not self-managed S3 buckets. If your organization is unable to rotate the IAM keys on their Cisco-managed S3 bucket, we recommend that the organization uses a self-managed Amazon S3 bucket.
  • If the IAM keys on a Cisco-managed S3 bucket are not rotated within 90 days from when the keys were last rotated, the organization will lose access to the Cisco-managed S3 bucket.

     
    Secure Access continues to log events to the Cisco-managed S3 bucket, but the S3 bucket is not accessible.
  • Secure Access provides periodic notifications about the expiry date of the IAM key on the Cisco-managed S3 bucket.