Medium S3

S3 general purpose buckets should be encrypted at rest with AWS KMS keys

NISTISO 27001HIPAA

Description

Confirms that S3 buckets are encrypted at rest using AWS KMS keys.


Remediation

Encrypt S3 buckets at rest using AWS KMS keys.

Steps

  1. Sign in to the AWS Management Console and open the Amazon S3 console.
  2. Choose the bucket and click the 'Properties' tab.
  3. In 'Default encryption', click 'Edit'.
  4. Select 'AWS Key Management Service key (SSE-KMS)' and choose a KMS key.
  5. Save changes.

Compliance

NISTISO 27001HIPAA