DynamoDB encryption key settings need review

DynamoDB always encrypts stored data. Review the selected key type and organizational requirements rather than treating the setting as an encryption on/off switch.

Description

DynamoDB encrypts all user data at rest. In CloudFormation, setting SSEEnabled to false or omitting it selects an AWS owned key; it does not mean plaintext storage. Setting it to true selects an AWS managed key, while a separate KMSMasterKeyId can select a customer managed key.

Potential impact

  • The selected key type may not meet organizational key-management or audit requirements.
  • Removing required KMS permissions or disabling a key in use can affect data access. Encryption at rest does not restrict access by otherwise authorized users.

Remediation

  • Compare the table's actual key type with requirements. If AWS owned keys are permitted, there is no additional encryption switch to enable.
  • Set SSESpecification.SSEEnabled: true when an AWS managed key is required. If you must control key policies and lifecycle, also select an approved KMSMasterKeyId and prepare the required permissions.
  • Verify key status and reads and writes after changes. Retain keys needed to restore associated backups, and manage table permissions and network protection separately.

Examples

Both examples encrypt stored data. Choose a table name for your environment and the key-management arrangement you need.

AWS owned key

yaml
Resources:
  MyDynamoDBTable:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: my-table
      AttributeDefinitions:
        - AttributeName: id
          AttributeType: N
      KeySchema:
        - AttributeName: id
          KeyType: HASH
      ProvisionedThroughput:
        ReadCapacityUnits: 5
        WriteCapacityUnits: 5
      SSESpecification:
        SSEEnabled: false

This encrypts data with an AWS owned key. Verify that this key type meets organizational requirements.

AWS managed key

yaml
Resources:
  MyDynamoDBTable:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: my-table
      AttributeDefinitions:
        - AttributeName: id
          AttributeType: N
      KeySchema:
        - AttributeName: id
          KeyType: HASH
      ProvisionedThroughput:
        ReadCapacityUnits: 5
        WriteCapacityUnits: 5
      SSESpecification:
        SSEEnabled: true

Without a separate key ID, this uses the default DynamoDB AWS managed key. It does not select a customer managed key, and AWS KMS charges apply.

References