Designing Data Security Controls

Design data security with KMS, envelope encryption, ACM, and Secrets Manager.

In the SAA-C03 exam, data security means protecting data in two states: at rest and in transit. The key skill is knowing which tool to use and when.

 

AWS KMS — The Cloud's Key Vault

KMS (Key Management Service) creates, stores, and manages encryption keys. Think of it as a professional locksmith service. You lock and unlock your own doors (data), but you hand the actual keys to a specialist (KMS) for safekeeping.

Most AWS services — S3, RDS, EBS, Lambda, and more — integrate with KMS automatically. Simply set "encrypt this S3 bucket" and KMS handles key management behind the scenes.

 

Three Types of KMS Keys

AWS managed keys are created and managed automatically by AWS. One key exists per service (for example, aws/s3, aws/rds). No setup is required and AWS handles key rotation automatically. Most convenient but offers no custom control.

Customer managed keys (CMK) are created and managed by you. You control key policies, rotation schedules, and access permissions. Use these when compliance requirements demand it or when you need fine-grained access control.

AWS owned keys are used internally by AWS. Customers cannot see or manage them.

!3 types of KMS keys

Envelope Encryption — Efficiently Encrypting Large Data

There is a problem with encrypting data directly through KMS. KMS can only process up to 4 KB of data, and routing every encryption call through the KMS API creates a performance bottleneck.

Envelope encryption solves this in two steps:

Step 1: KMS generates a Data Encryption Key (DEK). This DEK is what actually encrypts the data.

Step 2: The DEK encrypts the large data locally without any KMS API calls. This is fast.

Step 3: The DEK itself is then encrypted by the KMS master key and stored safely alongside the data. Think of it as "put the key in an envelope, then lock the envelope."

This approach lets you encrypt massive amounts of data efficiently while keeping the master key safely inside KMS at all times.

 

Encryption in Transit — HTTPS and Certificate Management

Data also needs protection while moving across networks.

HTTPS/TLS is the standard for encrypting web traffic. It encrypts the communication between a user's browser and the server.

AWS Certificate Manager (ACM) provisions SSL/TLS certificates for free and renews them automatically. You never have to worry about certificate expiration. ACM integrates easily with CloudFront, ALB, and API Gateway.

Exam hint: "apply HTTPS to a custom domain" or "SSL/TLS certificate with automatic renewal" — choose ACM.

 

Secret Management — Safely Storing Passwords and API Keys

Hardcoding a database password directly in your code is extremely dangerous. AWS provides dedicated services to manage sensitive information securely.

| Service | Key Feature | Use Case | |---------|-------------|----------| | AWS Secrets Manager | Automatic secret rotation | DB passwords, API keys, OAuth tokens | | SSM Parameter Store | Hierarchical storage, free tier available | App config values, environment variables | | AWS CloudHSM | Physical hardware-based key management | Strict compliance environments |

Secrets Manager's automatic rotation feature is especially important. It uses a Lambda function to periodically change an RDS password and store the new one in Secrets Manager — all without changing any application code.

 

S3 Data Protection — Extra Safeguards Against Mistakes

S3 Block Public Access prevents S3 buckets from being accidentally made public, configurable at account or bucket level. You can set "new buckets are private by default" as a safety net.

S3 Object Lock implements a WORM (Write Once Read Many) model. Once stored, data cannot be deleted or modified for a set retention period. Common in financial, healthcare, and legal compliance scenarios.

Amazon Macie automatically detects personally identifiable information (PII) and other sensitive data in S3 buckets. It flags if credit card numbers, social security numbers, or similar data have accidentally been stored in S3.

 

Exam Key Points

"Efficient encryption of large data" — Envelope encryption (DEK encrypts data, CMK encrypts DEK)

"Manage key policies and rotation schedule yourself" — Customer Managed Key (CMK)

"Free SSL/TLS certificates with automatic renewal" — AWS Certificate Manager (ACM)

"Automatically rotate DB passwords" — AWS Secrets Manager

"Hierarchical app config storage, free" — SSM Parameter Store

"Physical hardware-based encryption, strict compliance" — AWS CloudHSM

"Prevent S3 bucket from being accidentally made public" — S3 Block Public Access

"Immutable data, no delete or modify, WORM model" — S3 Object Lock

"Automatically detect PII in S3" — Amazon Macie

KMS is a regional service — use multi-region keys or replicate keys to use across regions

Back to blog list