DynamoDB uses an AWS owned key

AWS owned keys also encrypt DynamoDB data. Choose a key type that meets requirements for policies, auditing and lifecycle control.

Description

DynamoDB's default AWS owned key encrypts stored data. You do not directly manage that key's policy or lifecycle; this does not mean the data is unencrypted.

Consider an AWS managed key when your organization needs visibility into key use in its account, or a customer managed key when it needs direct policy and lifecycle control. An AWS managed key does not give you unrestricted control over its key policy.

Potential impact

  • An AWS owned key may not meet organizational key-control or audit requirements.
  • Incorrect permissions or deletion schedules for a customer managed key can make a table or associated backups inaccessible.

Remediation

  • Compare required key control with the actual key type. There is no need to replace an AWS owned key that meets requirements.
  • When a customer managed key is required, set SSEEnabled: true, SSEType: KMS and an approved KMSMasterKeyId. Review key policies, permissions and rotation.
  • Test data access after changing keys and check which backups still need the previous key. Restrict table permissions independently of encryption at rest.

Examples

These alternatives select keys for the same table. When managing existing resources, review the change set, actual key policy and the requirements for restoring needed backups.

AWS owned key

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample CloudFormation template for DynamoDB with AWS-Owned CMK
Resources:
  DynamoDBOnDemandTable2:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: dynamodb-kms-0
      AttributeDefinitions:
        - AttributeName: pk
          AttributeType: S
      KeySchema:
        - AttributeName: pk
          KeyType: HASH
      BillingMode: PAY_PER_REQUEST
      SSESpecification:
        SSEEnabled: false

Stored data is encrypted with an AWS owned key. You do not manage its key policy directly.

Customer managed key

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample CloudFormation template for DynamoDB with customer managed CMK
Resources:
  dynamodbKMSKey:
    Type: AWS::KMS::Key
    Properties:
      Description: An example CMK

  DynamoDBOnDemandTable2:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: dynamodb-kms-0
      AttributeDefinitions:
        - AttributeName: pk
          AttributeType: S
      KeySchema:
        - AttributeName: pk
          KeyType: HASH
      BillingMode: PAY_PER_REQUEST
      SSESpecification:
        KMSMasterKeyId: !Ref dynamodbKMSKey
        SSEEnabled: true
        SSEType: KMS

A separate KMS key is created and associated with the table. Omission of a key policy uses the default policy, so review the permissions needed by the deployment principal and table users. Do not delete keys still used by data or needed for backup recovery.

References