Ensure the number of private gateways is within the AWS limit for each region
Description
Checks the number of private gateways in each AWS region in your account is not close to the AWS imposed limit. If the number of GWs approaches the limit in a particular VPC, you will receive an alert. NOTE: As per http://docs.aws.amazon.com/general/latest/gr/aws_service_limits.html Virtual private gateway per region limit is 5. This policy will trigger an alert if Virtual private gateway per region reached 80% (i.e. 4) of resource availability limit allocated.
Remediation
8. Under This Account section, select which IAM users and/or roles can use the CMK to encrypt/decrypt data with the AWS KMS API.