In the AWS Management Console, create an IAM policy for the CMK to define its permissions. Note the policy name because you'll need it when you create an IAM role to access the key.
In the search bar, search for
IAM
.
Under
Access Management
, navigate to
Policies
.
Click
Create Policy
, switch to the JSON view, and enter the following text: