SNS topic encrypted with an AWS managed key

Check whether the AWS managed SNS encryption key meets organizational key-control requirements.

Description

With alias/aws/sns, SNS encrypts stored message bodies using an AWS managed KMS key. Using this key does not itself mean plaintext storage or weaker encryption.

However, AWS manages the key policy and you cannot edit it. Use a customer-managed KMS key where the organization must directly control key policy and lifecycle.

Potential impact

Using the default key on a message path requiring customer-managed keys may fail organizational requirements. Incorrect key restrictions can interrupt publishing or delivery; topic policies and subscription destinations need review regardless of key type.

Remediation

  • When a customer-managed key is required, set kms_master_key_id to an actual symmetric encryption KMS key ARN or alias.
  • Review topic and key policies together, granting publishers and integrated services the key permissions they need.
  • Verify publishing and delivery after the change, and retain key access needed to process existing messages. Manage transit encryption and message-metadata protection separately.

Examples

These separate topics compare key selection. Keep the topic name unchanged when changing only the key of an existing topic.

AWS managed key

hcl
resource "aws_sns_topic" "example" {
  name              = "user-updates-topic"
  kms_master_key_id = "alias/aws/sns"
}

This encrypts stored message bodies using an AWS managed key.

Customer-managed key

hcl
resource "aws_sns_topic" "example" {
  name              = "sns_ecnrypted"
  kms_master_key_id = "alias/MyAlias"
}

Replace alias/MyAlias with the alias of the actual customer-managed key. Prepare the key policy and necessary use permissions as well.

References