Encryption is a necessity when storing data within the cloud—there is a level of trust given to AWS any time a customer stores data on their infrastructure. However, should this data be sensitive and confidential, additional measures should be put in place by us as the customer to ensure that the data is protected. This is often a requirement of many compliance regulations and governance controls that organizations are required to meet. AWS is aware of the importance of this factor and so has provided numerous methods and mechanisms of encryption to allow you to do just that.
Many AWS services come with some form of encryption, and in this chapter, we covered some of the most common services which are referenced within the certification. These services interact with the KMS, and so gaining a good understanding of this service and the different services and components...