Skip to content

AWS Kendra index Server side encryption does not use Customer Managed Keys (CMKs)

Description

This policy identifies Kendra index servers which are encrypted with default KMS keys and not with Keys managed by Customer. It is a best practice to use customer managed KMS Keys to encrypt your Kendra index server data. It gives you full control over the encrypted data.

Code Example

go
resource "aws_kendra_index" "pass" {
  name     = "example"
  role_arn = aws_iam_role.this.arn

  server_side_encryption_configuration {
    kms_key_id = data.aws_kms_key.this.arn
  }
}

Remediation

Terraform

  • Resource: aws_kendra_index
  • Arguments: server_side_encryption_configuration.kms_key_id

Rule Details

FieldValue
IDIAC-0310
SeverityLOW
IaC TypeTerraform
FrameworksTerraform
Checkov IDCKV_AWS_262

References