Description
DynamoDB's default AWS owned key encrypts stored data. You do not directly manage that key's policy or lifecycle; this does not mean the data is unencrypted.
Consider an AWS managed key when your organization needs visibility into key use in its account, or a customer managed key when it needs direct policy and lifecycle control. An AWS managed key does not give you unrestricted control over its key policy.
Potential impact
- An AWS owned key may not meet organizational key-control or audit requirements.
- Incorrect permissions or deletion schedules for a customer managed key can make a table or associated backups inaccessible.
Remediation
- Compare required key control with the actual key type. There is no need to replace an AWS owned key that meets requirements.
- When a customer managed key is required, set
SSEEnabled: true,SSEType: KMSand an approvedKMSMasterKeyId. Review key policies, permissions and rotation. - Test data access after changing keys and check which backups still need the previous key. Restrict table permissions independently of encryption at rest.
Examples
These alternatives select keys for the same table. When managing existing resources, review the change set, actual key policy and the requirements for restoring needed backups.
AWS owned key
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample CloudFormation template for DynamoDB with AWS-Owned CMK
Resources:
DynamoDBOnDemandTable2:
Type: AWS::DynamoDB::Table
Properties:
TableName: dynamodb-kms-0
AttributeDefinitions:
- AttributeName: pk
AttributeType: S
KeySchema:
- AttributeName: pk
KeyType: HASH
BillingMode: PAY_PER_REQUEST
SSESpecification:
SSEEnabled: false
Stored data is encrypted with an AWS owned key. You do not manage its key policy directly.
Customer managed key
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample CloudFormation template for DynamoDB with customer managed CMK
Resources:
dynamodbKMSKey:
Type: AWS::KMS::Key
Properties:
Description: An example CMK
DynamoDBOnDemandTable2:
Type: AWS::DynamoDB::Table
Properties:
TableName: dynamodb-kms-0
AttributeDefinitions:
- AttributeName: pk
AttributeType: S
KeySchema:
- AttributeName: pk
KeyType: HASH
BillingMode: PAY_PER_REQUEST
SSESpecification:
KMSMasterKeyId: !Ref dynamodbKMSKey
SSEEnabled: true
SSEType: KMS
A separate KMS key is created and associated with the table. Omission of a key policy uses the default policy, so review the permissions needed by the deployment principal and table users. Do not delete keys still used by data or needed for backup recovery.