Amazon Web Services
In this video, Will Cavin, a senior product manager for Amazon S3, provides an in-depth overview of Amazon S3's data encryption options. He explains the different types of encryption supported by S3, including client-side encryption, encryption in transit, and server-side encryption. Cavin details the three server-side encryption options: SSE-S3 (Amazon S3-managed keys), SSE-KMS (AWS Key Management Service), and SSE-C (customer-provided keys). He also discusses the automatic encryption of new objects uploaded to S3 since January 2023, the benefits of using S3 bucket keys to reduce AWS KMS request costs, and how to verify encryption status using Amazon S3 Storage Lens. The video emphasizes the importance of encryption as part of a defense-in-depth strategy for data protection in cloud storage.