A config rule that checks whether Amazon SNS topic is encrypted with AWS Key Management Service (AWS KMS). The rule is NON_COMPLIANT if the Amazon SNS topic is not encrypted with AWS KMS. The rule is also NON_COMPLIANT when encrypted KMS key is not present in kmsKeyIds input parameter.

This config rule supports the following parameters:

  • kmsKeyIds
    • Required: No
    • Type: CSV
    • Description:Comma separated list of AWS KMS key ARNs allowed for encrypting Amazon SNS Topic.

CloudFormation Template