Encrypting Data at Rest by Using AWS KMS and Auditing Key Usage with AWS CloudTrail

preview_player
Показать описание
In this demonstration, you will use the AWS Key Management Service (AMS KMS) to encrypt data at rest. You will create an AWS KMS key, and use it to encrypt Amazon Elastic Block Store (Amazon EBS) volumes. You will also see how AWS CloudTrail provides an audit log of AWS KMS key usage and how disabling the key affects data access.

00:00 - Intro
01:02 - Launch an EC2 instance with an unencrypted root EBS volume attached.
03:51 - Create an AWS KMS key
05:58 - Monitor AWS KMS activity by using AWS CloudTrail
08:14 - Encrypt the root volume of an existing EC2 instance
15:43 - Disable the encryption key and observe the effects
Рекомендации по теме