Server-Side Encryption (SSE) means AWS encrypts your data after receiving it and decrypts it when you access it. The encryption/decryption is transparent to your application.
Protecting stored data by encrypting it on disk so that it cannot be read without the encryption key, even if the storage media is compromised.
A cryptographic key managed by AWS Key Management Service used to encrypt and decrypt data across AWS services, with centralized key policies and automatic rotation.
A resource-based JSON policy attached to an S3 bucket that controls who can access the bucket and its objects, including cross-account and public access.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.