Which solution will meet these requirements?

1 Comment

  1. Samuel
    Author

    I structure that the answer is:
    Provision a separate AWS Key Management Service (AWS KMS) key for each customer. Encrypt the data server-side. In each KMS key policy, deny decryption of data for all principals except an IAM role that the customer provides.

Leave a Reply

Your email address will not be published. Required fields are marked *

20 − 3 =