Encryption and decryption
The team has now acquired a more complete knowledge of IAM, their identities, their policies, and how they can be used to grant or deny permissions to diverse resources. But a final consideration has to be made – encryption, which is not done by IAM:
Alex: I’d like to end the day with a very short description of encryption. Most data can be encrypted; sometimes, it is even mandatory, but it will be performed automatically, without you noticing it.
Harold: Are you talking about encryption in transit or encryption at rest?
Alex: With many of the services in AWS, you can choose both.
Raj: I assume encryption is not provided by IAM. I didn’t see that on the documentation, and it seems a different feature. Probably a separate service?
Alex: It is called KMS, short for Key Management Service.