Medium
S3
S3 general purpose buckets should be encrypted at rest with AWS KMS keys
NISTISO 27001HIPAA
Description
Confirms that S3 buckets are encrypted at rest using AWS KMS keys.
Remediation
Encrypt S3 buckets at rest using AWS KMS keys.
Steps
- Sign in to the AWS Management Console and open the Amazon S3 console.
- Choose the bucket and click the 'Properties' tab.
- In 'Default encryption', click 'Edit'.
- Select 'AWS Key Management Service key (SSE-KMS)' and choose a KMS key.
- Save changes.
Compliance
NISTISO 27001HIPAA