Description
SNS server-side encryption is enabled through KmsMasterKeyId and protects message bodies stored in the topic. This setting does not also encrypt topic or message metadata, or storage at subscribers.
Potential impact
Sensitive messages requiring encryption at rest may be handled without the required KMS protection.
Remediation
Specify a suitable symmetric encryption KMS key in KmsMasterKeyId. Check key permissions for SNS and publishers, and configure subscriber transport and storage protection separately.
Examples
These excerpts add encryption to MySNSTopic. Supply an actual usable key through KmsKeyId.
Before
yaml
Resources:
MySNSTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: "SampleTopic"
After
yaml
Resources:
MySNSTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: "SampleTopic"
KmsMasterKeyId: !Ref KmsKeyId