A KMS Key (formerly called a Customer Master Key or CMK) is a cryptographic key created and managed in AWS Key Management Service. KMS keys are used to encrypt data across 70+ AWS services - S3, EBS, RDS, DynamoDB, Secrets Manager, and more.
Protecting stored data by encrypting it on disk so that it cannot be read without the encryption key, even if the storage media is compromised.
A two-tier encryption strategy where data is encrypted with a data key, and the data key itself is encrypted with a master key (KMS key), combining performance with security.
Periodically replacing cryptographic keys with new ones to limit the impact of a potential key compromise, supported automatically by AWS KMS.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.