Summary
In this chapter, we looked at protecting your data both at rest and in transit in your Amazon account. We began truly at an account level, looking at how to implement encryption during the transmission of data to your VPC using secure VPN connections over an IPSec tunnel. After that, we took a look at KMS and the differences between an Amazon-managed key and a CMK. Finally, we looked at securing data in transit using ACM. We saw how easy ACM makes it to create and implement SSL and TLS certificates on several AWS services.
In the next chapter, we will look at how to enforce standards and compliance within your organization with two powerful automation tools offered by AWS: Systems Manager and Config.