AWS documentdb: Updated encryption key terminology and IAM policy clarity
Summary
Changed 'Customer Key' to 'customer managed key' and 'Data Keys' to 'data keys' for consistency. Improved IAM policy language for KMS access.
Security assessment
Evidence shows improved documentation of encryption key management best practices, emphasizing security posture without fixing a vulnerability.
Evidence
+Using AWS Key Management Service, create a symmetric customer managed key that encrypts and decrypts the sensitive data field, and grant it the necessary IAM usage permissions. AWS KMS stores the customer managed key, which is used to encrypt data keys. Storing the customer managed key in AWS KMS strengthens your security posture.
Diff
diff --git a/documentdb/latest/devguide/field-level-encryption.md b/documentdb/latest/devguide/field-level-encryption.md index e610e5035..6cc790322 100644 --- a//documentdb/latest/devguide/field-level-encryption.md +++ b//documentdb/latest/devguide/field-level-encryption.md @@ -43 +43 @@ The initial configuration of client-side FLE in Amazon DocumentDB is a four-step -Using AWS Key Management Service, create a symmetric key that is used for encrypting and decrypting the sensitive data field and provide it the necessary IAM usage permissions. AWS KMS stores the Customer Key (CK) which is used to encrypt Data Keys (DKs). Store the Customer Key in KMS to strengthen your security posture. The Data Key is the secondary key which is stored in an Amazon DocumentDB collection and is required to encrypt sensitive fields before storing the document in Amazon DocumentDB. The Customer Key encrypts the Data Key which in turn encrypts and decrypts your data. If you are using a global cluster, you can create a multi-Region key that can be used by different service roles in different Regions. +Using AWS Key Management Service, create a symmetric customer managed key that encrypts and decrypts the sensitive data field, and grant it the necessary IAM usage permissions. AWS KMS stores the customer managed key, which is used to encrypt data keys. Storing the customer managed key in AWS KMS strengthens your security posture. The data key is the secondary key, which is stored in an Amazon DocumentDB collection and is required to encrypt sensitive fields before storing the document in Amazon DocumentDB. The customer managed key encrypts the data key, which in turn encrypts and decrypts your data. If you use a global cluster, you can create a multi-Region key that different service roles can use in different Regions. @@ -49 +49 @@ For more information about the AWS Key Management Service, including how to crea -Create an IAM policy with appropriate AWS KMS permissions. This policy allows IAM identities to which it is attached to encrypt and decrypt the KMS key specified in resource field. Your application assumes this IAM role to authenticate with AWS KMS. +Create an IAM policy with appropriate AWS KMS permissions. This policy allows the IAM identities to which it is attached to encrypt and decrypt the KMS key specified in the resource field. Your application assumes this IAM role to authenticate with AWS KMS. @@ -61 +61 @@ The policy should look similar to this: -By now you defined a Customer Key in AWS KMS and created an IAM role and provided it the right IAM permissions to access the Customer Key. Import the required packages. +You have defined a customer managed key in AWS KMS and created an IAM role with the necessary permissions to access it. Import the required packages. @@ -78 +78 @@ By now you defined a Customer Key in AWS KMS and created an IAM role and provide - 1. Specify ‘aws’ as KMS provider type and enter your account credentials which were retrieved in the previous step. + 1. Specify `aws` as the AWS KMS provider type and enter the account credentials that you retrieved in the previous step. @@ -88 +88 @@ By now you defined a Customer Key in AWS KMS and created an IAM role and provide - 2. Specify the customer key which is used to encrypt the data key: + 2. Specify the customer managed key to encrypt the data key: @@ -113 +113 @@ By now you defined a Customer Key in AWS KMS and created an IAM role and provide - 4. Generate your Data Key: + 4. Generate your data key: @@ -119 +119 @@ By now you defined a Customer Key in AWS KMS and created an IAM role and provide - 5. Retrieve your existing Data Key: + 5. Retrieve your existing data key: