S3 Encryption and KMS Key Policy Audit Checklist
Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.
KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.
S3 encryption
- Default encryption configured on every bucket (SSE-S3 minimum; SSE-KMS for sensitive buckets).
- S3 Bucket Keys enabled for SSE-KMS buckets.
- Bucket policies deny uploads without the required encryption where needed.
- SSE-C blocked where not used.
- Older unencrypted objects identified (S3 Inventory reports encryption status) and re-encrypted if required.
KMS key policies
- Each customer managed key has a named owner.
- Key administrators (who can change policy, schedule deletion) are separate from key users (who can encrypt/decrypt).
- No key policy grants
kms:*to broad principals. - Cross-account access to keys is explicit and documented.
- The root account principal statement is understood (it delegates to IAM policies).
- Key rotation enabled for symmetric customer managed keys.
Deletion protection
- Scheduled key deletion requires a waiting period (7–30 days).
- Alerts fire on
ScheduleKeyDeletionandDisableKey. - SCPs restrict key deletion to a break-glass role.
Monitoring
- CloudTrail logs KMS
Decryptevents for sensitive keys. - Unusual decrypt volume or new principals trigger review.
Review
- Key policies reviewed annually and when teams change.
- AWS Encrypts All New S3 Objects by Default (Jan 2023) Platform Changes
- How to Choose Between SSE-S3, SSE-KMS and DSSE-KMS for S3 How-To & Hardening
- CIO Brief: Encryption by Default — What It Does and Doesn't Protect CIO Briefings