Kinesis stream without server-side encryption

Encrypt Kinesis stream data at rest and verify access for producers and consumers.

Description

Kinesis Data Streams server-side encryption uses a KMS key to encrypt records before storage and decrypt them when read. An unencrypted stream lacks this protection for stored events or logs. Encryption does not restrict consumers that already have legitimate read access.

Potential impact

Unauthorized acquisition of stored data can expose sensitive information in customer events or operational logs. The stream may also fail to meet organizational data-protection requirements.

Remediation

Configure StreamEncryption with EncryptionType: KMS and a valid KeyId. Use an AWS managed key or choose a customer managed key for the organization’s key-management and cross-account sharing requirements. Verify the key policy and the permissions producers and consumers need.

Enabling encryption is asynchronous. After it takes effect, verify encryption of new records and successful writes and reads. Previously stored unencrypted records are not encrypted retroactively, so also review retention and treatment of existing data.

Examples

These examples compare settings for the same stream. Manage access policies and encryption in transit separately.

Before

yaml
Resources:
  EventStream:
    Type: AWS::Kinesis::Stream
    Properties:
      Name: EventStream
      RetentionPeriodHours: 24
      ShardCount: 1
      Tags:
        - Key: Name
          Value: EventStream

After

yaml
Resources:
  EventStream:
    Type: AWS::Kinesis::Stream
    Properties:
      Name: EventStream
      RetentionPeriodHours: 24
      ShardCount: 1
      StreamEncryption:
        EncryptionType: KMS
        KeyId: alias/aws/kinesis
      Tags:
        - Key: Name
          Value: EventStream

This uses the AWS managed alias/aws/kinesis key. When a customer managed key is required, such as for cross-account sharing, use an appropriate key and permissions.

References