What should the company do next to meet these requirements?

1 Comment

  1. Sandra
    Author

    As far as I can tell, the answer is:
    Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.

Leave a Reply

Your email address will not be published. Required fields are marked *

8 + seven =