You are a data administrator and your organization has stored huge volumes of data in a relational database. You want to collate legacy sales data to track the overall growth trend in sales from the relational database and archive it on Amazon S3. In addition, you want to secure the legacy data of your organization to avoid random access by unauthorized persons. You can enable Client-side encryption using the customer master key to encrypt data. You can read data from the relational database and use Amazon S3 Connector to upload data to Amazon S3.
You can configure AWS KMS customer master key to encrypt data to Amazon S3. You can specify a customer master key while creating an Amazon S3 connection. The Customer master key offers more control and permissions on the key to control who can use or manage the key.
Perform the following tasks to configure AWS KMS customer master key to encrypt data:
Generate a customer master key in AWS Key Management Service.