3.3.1.1. Data Protection Strategies (Encryption at Rest/Transit, KMS, CloudHSM, Macie)
3.3.1.1. Data Protection Strategies (Encryption at Rest/Transit, KMS, CloudHSM, Macie)
💡 First Principle: Safeguarding sensitive information from unauthorized access, modification, or destruction necessitates encryption throughout the data lifecycle, ensuring confidentiality, integrity, and regulatory compliance.
Scenario: A healthcare application stores sensitive patient data in an "Amazon S3" bucket and a relational database on "Amazon RDS". This data is accessed by a web application via "HTTPS". The organization has strict compliance requirements (e.g., "HIPAA") that mandate encryption for all sensitive data both at rest and in transit.
Data protection is a critical security pillar, implemented through various encryption and classification strategies.
- Encryption at Rest: Protects data while stored on disk.
- "AWS Key Management Service (KMS)": A managed service for creating and controlling encryption keys. Integrates with most AWS services (
"S3","EBS","RDS","Lambda","EFS") for encrypting data at rest ("SSE-KMS"). Provides audit trails via"CloudTrail". - "AWS CloudHSM": A cloud-based hardware security module (
"HSM"). Allows you to generate and use your own encryption keys on"FIPS 140-2 Level 3"validated hardware. For highly sensitive data and strict compliance. - S3 Encryption:
"SSE-S3"(S3-managed keys),"SSE-KMS"(KMS-managed keys),"SSE-C"(Customer-provided keys). - EBS Encryption: Encrypts
"EBS volumes"and snapshots automatically using"KMS".
- "AWS Key Management Service (KMS)": A managed service for creating and controlling encryption keys. Integrates with most AWS services (
- Encryption in Transit: Protects data as it moves over networks.
- TLS/SSL: Fundamental for securing communication channels (e.g.,
"HTTPS"for"ALBs","API Gateway","CloudFront"; SSL for database connections). - "AWS Certificate Manager (ACM)": Provision, manage, and deploy SSL/TLS certificates for integrated AWS services. Automates renewal.
- TLS/SSL: Fundamental for securing communication channels (e.g.,
- "Amazon Macie": A security service that uses machine learning to discover, classify, and protect sensitive data in
"S3".- Practical Relevance: Identifies
"PII", financial data, and other sensitive information, and detects unusual access patterns. Crucial for data visibility and compliance (e.g.,"GDPR","HIPAA").
- Practical Relevance: Identifies
Visual: Data Protection Strategies
Key Choices, Secrets and S3 Details:
- Which KMS key:
"AWS managed keys"(such asaws/s3andaws/ebs) are created and rotated by the service and you cannot edit their key policy or control rotation."Customer managed keys"let you write the key policy and grants, control rotation and disable or delete the key, and every use is logged in"CloudTrail"; choose them when a requirement says control rotation, access policy or audit. For S3:"SSE-S3"when AWS should handle everything with no key control,"SSE-KMS"when you need key policy and audit,"SSE-C"when the client supplies the key on every request, client-side encryption when keys never leave the application. EBS encryption-by-default can be turned on per Region with a customer managed key. - Cross-account KMS use: A caller in another account needs the key policy (in the key's account) to allow its account or role for the needed actions (for example
kms:GenerateDataKeyto write andkms:Decryptto read SSE-KMS objects) and its own IAM policy to allow them on the key ARN. A bucket policy alone does not unlock the key, and keys are Regional and do not replicate into the caller's account. - CloudHSM with native encryption: KMS keys live in multi-tenant, AWS-managed HSMs. Only
"CloudHSM"gives single-tenant"FIPS 140-2 Level 3"hardware that you alone control. To still drive S3 and EBS server-side encryption, create a KMS custom key store backed by your CloudHSM cluster;"SSE-C"and OS-level encryption do not integrate with AWS-service encryption. - Secrets:
"Secrets Manager"stores credentials and API keys encrypted with KMS, returns them at runtime to authorized IAM roles (each retrieval appears in"CloudTrail"), supports resource policies for cross-account use and versioning, and its distinguishing feature is built-in scheduled rotation (for"RDS"/"Aurora"it updates both the secret and the database)."Systems Manager Parameter Store"SecureString parameters are KMS-encrypted and versioned and cost less, but have no native automatic rotation. On"ECS"/"Fargate"reference the secret in the container definition'ssecretsfield; the task execution role needs permission to read it. Plain environment variables, config files, user data, source code, AMIs and unmanaged S3 objects are not secret stores and cannot rotate. - TLS to the targets: An HTTPS listener with an
"ACM"certificate ends TLS at the"ALB", which leaves the ALB-to-instance hop in clear text. For every hop encrypted, set the target group protocol to HTTPS and install a certificate on the targets (the ALB does not validate it, so self-signed works)."VPC Flow Logs"record metadata and encrypt nothing. - Existing S3 objects: Default encryption applies to objects written after it is enabled. To encrypt existing objects, copy them over themselves with the new settings; at scale use
"S3 Batch Operations"(a Copy job driven by an S3 Inventory report or manifest)."Macie"also reports bucket-level posture (public access, encryption, sharing) beside its sensitive-data scans. To confine a bucket to a VPC, use a gateway endpoint plus a bucket policy onaws:SourceVpceoraws:SourceVpc. - Immutable storage (S3 Object Lock): Write-once-read-many per object version (needs versioning). Compliance mode: no one, including root, can delete, overwrite or shorten retention until it expires. Governance mode: principals with
s3:BypassGovernanceRetentioncan override. Legal hold has no end date until removed. Object Lock protects objects, not the account, so to survive account closure replicate ("CRR") to a bucket in a separate, isolated account that also has Object Lock;"Intelligent-Tiering"or lifecycle tiering keeps data readable and cheaper while retention still applies. MFA Delete, IAM policies, bucket policies and"SCPs"are not WORM, because an administrator can change them. The legacy Glacier vault API (and its Vault Lock) no longer accepts new customers; for archives, use the S3 Glacier storage classes with Object Lock.
⚠️ Common Pitfall: Believing that encryption is the only data protection needed. Encryption protects confidentiality, but you still need strong "IAM policies" to control access to the data and the encryption keys themselves.
Key Trade-Offs:
- Managed Keys (
"KMS") vs. Full Control ("CloudHSM"):"KMS"is easier to use and integrates seamlessly, but AWS manages the hardware."CloudHSM"provides dedicated, single-tenant hardware and more control, which may be required for certain compliance regimes, but at a higher cost and operational overhead.
Reflection Question: How would you implement a comprehensive data protection strategy using "AWS KMS", "S3" encryption, "RDS" encryption, and "AWS Certificate Manager (ACM)" to meet the at-rest and in-transit encryption requirements for a healthcare application processing sensitive patient data under "HIPAA" compliance mandates?