SNS topic KMS encryption not configured

Configure required encryption for stored message bodies.

Description

SNS server-side encryption is enabled through KmsMasterKeyId and protects message bodies stored in the topic. This setting does not also encrypt topic or message metadata, or storage at subscribers.

Potential impact

Sensitive messages requiring encryption at rest may be handled without the required KMS protection.

Remediation

Specify a suitable symmetric encryption KMS key in KmsMasterKeyId. Check key permissions for SNS and publishers, and configure subscriber transport and storage protection separately.

Examples

These excerpts add encryption to MySNSTopic. Supply an actual usable key through KmsKeyId.

Before

yaml
Resources:
  MySNSTopic:
    Type: AWS::SNS::Topic
    Properties:
      TopicName: "SampleTopic"

After

yaml
Resources:
  MySNSTopic:
    Type: AWS::SNS::Topic
    Properties:
      TopicName: "SampleTopic"
      KmsMasterKeyId: !Ref KmsKeyId

References