Ensure that your Amazon Bedrock Studio workspaces are encrypted with Amazon KMS Customer Managed Keys (CMKs) instead of AWS managed keys. This grants you more granular control over the data encryption at rest and helps meet compliance requirements.
excellence
Amazon Bedrock Studio workspaces are collaborative environments used for developing, training, and deploying machine learning (ML) models on AWS. By default, Amazon Bedrock Studio encrypts your workspace data with an AWS-managed key. When you use your own KMS Customer Managed Keys (CMKs) to protect your data, you have full control over who can use the encryption keys to access your data. Encrypting your Studio workspaces is necessary to protect sensitive data and ensure compliance with security standards and regulations. The Amazon KMS service allows you to easily create, rotate, disable, and audit Customer Managed Keys for your Amazon Bedrock Studio workspaces.
Audit
To obtain the encryption configuration available for your Amazon Bedrock Studio Workspaces, perform the following operations:
Getting the workspace encryption configuration information via AWS Command Line Interface (CLI) is not currently supported.Remediation / Resolution
To encrypt your Amazon Bedrock Studio workspaces using your own KMS Customer Master Key (CMK), you must re-create your workspaces with the necessary encryption configuration, by performing the following operations:
Encrypting your Amazon Bedrock Studio workspaces using AWS Command Line Interface (CLI) is not currently supported.