< ciso
brief />
Tag Banner

All news with #aws kms tag

43 articles

Improving SPIRE Security and Resiliency on AWS

๐Ÿ”’ This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more โ†’

Amazon Transcribe adds customer-managed KMS keys

๐Ÿ” Amazon Transcribe now allows encryption of custom vocabularies, custom vocabulary filters, and custom language models at rest using a customer-managed AWS KMS symmetric key that you own and control. Previously these artifacts were encrypted with an AWS-owned key; if you do not provide a key, encryption continues under the AWS-owned key. Using a customer-managed key provides control over key permissions, CloudTrail logging for key usage, and the ability to disable or rotate keys to revoke access. The feature is available in all Regions where Amazon Transcribe is offered.
read more โ†’

Architecting resilient authentication with Cognito MRR

๐Ÿ”’ Amazon Cognito now supports multi-Region replication (MRR) to automatically replicate user pools across AWS Regions with near-real-time synchronization, built-in failover, and interoperable JWT sessions. Replica user pools support sign-in and token operations but are read-only for configuration and attribute writes, which must be performed in the primary Region. To use MRR you must configure a symmetric multi-Region AWS KMS customer managed key and consider adopting the updated multi-Region OIDC issuer to ensure consistent discovery and JWKS endpoints. Cognito supports automatic domain and OAuth failover via Route 53 health checks and recommends using infrastructure-as-code and JWKS caching strategies for smooth migration and operational continuity.
read more โ†’

EBS Volume Clones: Crossโ€‘Account Copy Support

๐Ÿ”’ Amazon Elastic Block Store (Amazon EBS) Volume Clones now supports copying volumes across AWS accounts with reโ€‘encryption using AWS Key Management Service (AWS KMS) keys in the target account. This lets organizations segregate production and development accounts while sharing data safely. The feature supports all volume types, including unencrypted and customerโ€‘managed KMSโ€‘encrypted volumes, and is available via the Console, CLI, and SDKs in supported Regions.
read more โ†’

SageMaker MLflow Adds Support for Customer Keys

๐Ÿ” SageMaker MLflow now supports customer-managed keys (CMK) via AWS Key Management Service (KMS). This enhancement lets organizations with strict security or compliance needs manage encryption keys themselves and gain enhanced control and auditing through AWS CloudTrail. Customer-managed keys must be symmetric and created in the same AWS account and region as the MLflow App. The feature is generally available in all Regions where MLflow App is offered.
read more โ†’

Timestream for InfluxDB adds customer managed KMS

๐Ÿ” Amazon Timestream for InfluxDB now supports AWS KMS customer managed keys to encrypt data at rest for InfluxDB 2 databases, InfluxDB 2 Read Replicas, and InfluxDB 3 clusters. Customers choose a symmetric AWS KMS key during resource creation; the key must reside in the same AWS account and Region and cannot be changed later. The capability is available via the AWS Console, AWS CLI, and the Timestream for InfluxDB API across all supported Regions, with standard AWS KMS charges applying.
read more โ†’

Timestream for InfluxDB adds backup and restore

๐Ÿ”’ Amazon Timestream for InfluxDB now supports customer-driven backups and restores for InfluxDB 2 and 3 engines. You can trigger one-time on-demand backups, schedule up to four recurring backup configurations per resource with custom frequency and retention, and restore either to a new resource or overwrite an existing one via the Console, CLI, or API. The first backup is full and subsequent backups are incremental, and KMS-managed keys are preserved for encrypted resources.
read more โ†’

Caching KMS Data Keys to Prevent Cache Stampedes

๐Ÿ” This post examines how NICE Actimize reduced AWS KMS costs by 77% for a multi-tenant, event-driven platform by rethinking data key caching. It outlines the cache stampede problem that arises when envelope encryption operates at high concurrency and describes two solutions: the AWS-recommended hierarchical keyring with DynamoDB branch keys and a custom CachedKmsClient using Caffeine caches. The article covers design, trade-offs, and security considerations for both patterns.
read more โ†’

AWS Glue Data Catalog adds S3 Tables export

๐Ÿ”” Today AWS Glue Data Catalog preview adds two features: exporting catalog metadata to S3 Tables and enabling semantic search for catalogs encrypted with customer managed AWS KMS keys. Exported metadata โ€” including glossary terms, custom attachments, and descriptions โ€” is written to the managed aws-catalog S3 table bucket in Apache Iceberg format, enabling SQL queries, auditing, and time travel in engines like Amazon Athena and third-party tools. These capabilities are available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Ireland); S3 Tables usage follows S3 pricing.
read more โ†’

Choosing AWS KMS or AWS CloudHSM for Key Management

๐Ÿ” This post compares AWS KMS and AWS CloudHSM, explaining their differences, deployment models, pricing, region coverage, and typical use cases. It emphasizes that AWS KMS is the recommended, fully managed option for most workloads while CloudHSM is appropriate for legacy applications or strict dedicated-HSM requirements. The article outlines shared security assurances, compliance coverage, supported algorithms, and operational trade-offs to guide selection.
read more โ†’

Lambda durable functions add customer managed KMS support

๐Ÿ”’ AWS Lambda durable functions now support encrypting durable execution data with an AWS KMS customer managed key. Durable functions let you run long-lived workflows with automatic state management; execution state is encrypted at rest by default with an AWSโ€‘owned key. With this update you can select and manage your own KMS key for execution data, enabling separate control of rotation and access for execution history and state. The feature is available in all Regions where durable functions exist; standard AWS KMS charges apply.
read more โ†’

CloudWatch Synthetics adds customer managed KMS keys

๐Ÿ” Amazon CloudWatch Synthetics now supports using customer managed AWS KMS keys to encrypt canary environment variables, allowing teams to control encryption for sensitive data such as API keys and tokens. Previously, only an AWS owned key was used; now you can specify a symmetric KMS key for at-rest encryption or perform client-side encryption and decrypt at runtime. This capability meets requirements for key management, auditability, and rotation and is available in all commercial AWS Regions, with multi-location canaries able to use per-replica Region keys.
read more โ†’

Amazon S3 delivers server access logs to CloudWatch

๐Ÿ“ฃ Amazon S3 now supports delivering server access logs to Amazon CloudWatch Logs, enabling instant querying, alarms, cross-account and cross-Region aggregation, and AWS KMS encryption for access log data. You can also mirror logs to Amazon S3 Tables in Apache Iceberg format at no additional storage cost. These delivery options complement existing free delivery to S3 buckets and provide more flexibility for monitoring and analysis.
read more โ†’

Amazon Cognito adds customer managed KMS keys

๐Ÿ” Amazon Cognito now supports customer managed keys in AWS Key Management Service (KMS) to encrypt user pool data at rest. While AWS-owned keys remain the default, customer managed keys let organizations control key lifecycle and access policies to meet governance requirements. You can set a key when creating a new user pool or update an existing one, and audit key usage via AWS CloudTrail. Available in Essentials and Plus tiers with standard AWS KMS charges.
read more โ†’

AWS KMS GetKeyLastUsage improves key audits

๐Ÿ” AWS KMS introduced the GetKeyLastUsage API to report the date, time, operation type, CloudTrail event ID, and KMS request ID for the most recent cryptographic operation on a key. The feature works for customer-managed and AWS-managed keys across specs and origins and is visible in the AWS Management Console and AWS CLI. Tracking of last usage began on April 23, 2026 for most Regions, so historical gaps before tracking began should be considered. Use DisableKey, monitoring, and the kms:TrailingDaysWithoutKeyUsage condition to prevent accidental deletions.
read more โ†’

Amazon Quick Research adds customer-managed KMS keys

๐Ÿ”’ Amazon Quick Research now supports encryption using customer-managed keys (CMKs) via AWS Key Management Service, enabling organizations to control encryption, auditing, and key lifecycle. Customers can use multiple CMKs with one default key per AWS account per region and must create CMKs in the same account and region as Quick resources. Only symmetric KMS keys are supported, and CloudTrail integration provides comprehensive audit trails and the ability to revoke compromised keys within 15 minutes. The feature is generally available in all AWS Regions where Amazon Quick is offered.
read more โ†’

Amazon Quick Research adds customer-managed KMS keys

๐Ÿ” Amazon Quick Research now supports customer-managed keys (CMKs) via AWS Key Management Service (KMS), enabling organizations to manage encryption keys for their Quick data. Customer-managed keys provide enhanced control, CloudTrail-based auditing, and the ability to revoke compromised keys within 15 minutes. Only symmetric KMS keys created in the same account and region are supported, with one default CMK per account per region and support for multiple CMKs across datasets.
read more โ†’

SageMaker HyperPod Adds Data Capture for Inference

๐Ÿงพ Amazon SageMaker HyperPod now supports data capture for inference workloads, allowing organizations to record request and response payloads for monitoring, compliance, debugging, and offline analysis. You can capture traffic at the SageMaker endpoint, load balancer, or model pod and combine layers for richer observability. Captured data is delivered asynchronously to Amazon S3 with configurable sampling and encryption using customer-managed AWS KMS keys and is designed to never block inference. Enable data capture via the HyperPod Inference Operator or SageMaker JumpStart.
read more โ†’

AWS Transform Adds Customer-Owned S3 Artifact Storage

๐Ÿ—‚๏ธ AWS Transform now supports customer-owned Amazon S3 buckets, letting customers control where transformation artifacts are stored and how they are secured. You can configure your own S3 bucket, optionally encrypt artifacts with your AWS KMS key, and manage access policies in your account. Migration teams can upload files directly and centralize artifacts across accounts to support regulated industries and data sovereignty requirements. This capability is available in all Regions where AWS Transform is offered.
read more โ†’

AWS Payment Cryptography Achieves PCI PIN and P2PE

๐Ÿ”’ AWS announced the completion of PCI PIN and PCI P2PE assessments for AWS Payment Cryptography, expanding validations to include Key Management (KMCP) and Key Loading (KLCP) alongside the existing Decryption Management (DMCP). The coverage is extended to South America (Sรฃo Paulo) and Asia Pacific (Sydney) Regions. These attestations allow customers to use PCI PTS HSM-certified, AWS-managed HSMs with compliant key management to simplify regulated deployments.
read more โ†’