Description
DynamoDB encrypts all user data at rest. In CloudFormation, setting SSEEnabled to false or omitting it selects an AWS owned key; it does not mean plaintext storage. Setting it to true selects an AWS managed key, while a separate KMSMasterKeyId can select a customer managed key.
Potential impact
- The selected key type may not meet organizational key-management or audit requirements.
- Removing required KMS permissions or disabling a key in use can affect data access. Encryption at rest does not restrict access by otherwise authorized users.
Remediation
- Compare the table's actual key type with requirements. If AWS owned keys are permitted, there is no additional encryption switch to enable.
- Set
SSESpecification.SSEEnabled: truewhen an AWS managed key is required. If you must control key policies and lifecycle, also select an approvedKMSMasterKeyIdand prepare the required permissions. - Verify key status and reads and writes after changes. Retain keys needed to restore associated backups, and manage table permissions and network protection separately.
Examples
Both examples encrypt stored data. Choose a table name for your environment and the key-management arrangement you need.
AWS owned key
Resources:
MyDynamoDBTable:
Type: AWS::DynamoDB::Table
Properties:
TableName: my-table
AttributeDefinitions:
- AttributeName: id
AttributeType: N
KeySchema:
- AttributeName: id
KeyType: HASH
ProvisionedThroughput:
ReadCapacityUnits: 5
WriteCapacityUnits: 5
SSESpecification:
SSEEnabled: false
This encrypts data with an AWS owned key. Verify that this key type meets organizational requirements.
AWS managed key
Resources:
MyDynamoDBTable:
Type: AWS::DynamoDB::Table
Properties:
TableName: my-table
AttributeDefinitions:
- AttributeName: id
AttributeType: N
KeySchema:
- AttributeName: id
KeyType: HASH
ProvisionedThroughput:
ReadCapacityUnits: 5
WriteCapacityUnits: 5
SSESpecification:
SSEEnabled: true
Without a separate key ID, this uses the default DynamoDB AWS managed key. It does not select a customer managed key, and AWS KMS charges apply.