Description
Kinesis Data Streams server-side encryption uses a KMS key to encrypt records before storage and decrypt them when read. An unencrypted stream lacks this protection for stored events or logs. Encryption does not restrict consumers that already have legitimate read access.
Potential impact
Unauthorized acquisition of stored data can expose sensitive information in customer events or operational logs. The stream may also fail to meet organizational data-protection requirements.
Remediation
Configure StreamEncryption with EncryptionType: KMS and a valid KeyId. Use an AWS managed key or choose a customer managed key for the organization’s key-management and cross-account sharing requirements. Verify the key policy and the permissions producers and consumers need.
Enabling encryption is asynchronous. After it takes effect, verify encryption of new records and successful writes and reads. Previously stored unencrypted records are not encrypted retroactively, so also review retention and treatment of existing data.
Examples
These examples compare settings for the same stream. Manage access policies and encryption in transit separately.
Before
Resources:
EventStream:
Type: AWS::Kinesis::Stream
Properties:
Name: EventStream
RetentionPeriodHours: 24
ShardCount: 1
Tags:
- Key: Name
Value: EventStream
After
Resources:
EventStream:
Type: AWS::Kinesis::Stream
Properties:
Name: EventStream
RetentionPeriodHours: 24
ShardCount: 1
StreamEncryption:
EncryptionType: KMS
KeyId: alias/aws/kinesis
Tags:
- Key: Name
Value: EventStream
This uses the AWS managed alias/aws/kinesis key. When a customer managed key is required, such as for cross-account sharing, use an appropriate key and permissions.