Description
SNS topics carry notifications and operational events. Server-side encryption encrypts received message bodies with a KMS key for storage and decrypts them for delivery. A topic with encryption disabled lacks this layer of protection at rest.
This feature does not encrypt metadata such as topic names, message subjects and attributes. Keep sensitive information out of metadata and restrict publishing and subscription permissions separately.
Potential impact
Unencrypted messages lack this protection against stored-data exposure and may not meet organizational encryption requirements. Incorrect key permissions can also disrupt legitimate publishing or delivery.
Remediation
- Set
kms_master_key_idto a symmetric KMS key and configure the key permissions required by publishers and integrated services. - Use HTTPS and Signature Version 4 for requests to encrypted topics. Test the actual publishing and subscription flow after the change.
- Encryption applies to messages published after it is enabled, not to an existing backlog. Review storage encryption and access policies at subscription destinations separately.
Examples
These excerpts show topic settings. Replace alias/MyAlias with an actual key alias in the Region and configure the required permissions.
Before
resource "aws_sns_topic" "user_updates" {
name = "user-updates-topic"
kms_master_key_id = ""
}
The key for stored-message encryption is empty.
After
resource "aws_sns_topic" "user_updates" {
name = "user-updates-topic"
kms_master_key_id = "alias/MyAlias"
}
This encrypts new message bodies with the specified key. The setting does not also protect all metadata or data at subscription destinations.