SNS topic without message encryption

Encrypt message bodies stored in SNS with KMS and protect publishing permissions and delivery paths.

Description

SNS topics carry notifications and operational events. Server-side encryption encrypts received message bodies with a KMS key for storage and decrypts them for delivery. A topic with encryption disabled lacks this layer of protection at rest.

This feature does not encrypt metadata such as topic names, message subjects and attributes. Keep sensitive information out of metadata and restrict publishing and subscription permissions separately.

Potential impact

Unencrypted messages lack this protection against stored-data exposure and may not meet organizational encryption requirements. Incorrect key permissions can also disrupt legitimate publishing or delivery.

Remediation

  • Set kms_master_key_id to a symmetric KMS key and configure the key permissions required by publishers and integrated services.
  • Use HTTPS and Signature Version 4 for requests to encrypted topics. Test the actual publishing and subscription flow after the change.
  • Encryption applies to messages published after it is enabled, not to an existing backlog. Review storage encryption and access policies at subscription destinations separately.

Examples

These excerpts show topic settings. Replace alias/MyAlias with an actual key alias in the Region and configure the required permissions.

Before

hcl
resource "aws_sns_topic" "user_updates" {
  name              = "user-updates-topic"
  kms_master_key_id = ""
}

The key for stored-message encryption is empty.

After

hcl
resource "aws_sns_topic" "user_updates" {
  name              = "user-updates-topic"
  kms_master_key_id = "alias/MyAlias"
}

This encrypts new message bodies with the specified key. The setting does not also protect all metadata or data at subscription destinations.

References