AWS Backup now supports AWS KMS customer managed keys with logically air-gapped vaults
Share
Services
AWS Backup now supports encrypting backups in logically air-gapped vaults with AWS Key Management Service (KMS) customer managed keys (CMKs). This enhancement provides additional encryption options beyond the existing AWS-owned keys, helping organizations meet their regulatory and compliance requirements.
You can now create logically air-gapped vaults using your own customer managed keys (CMKs) in AWS KMS, giving you more control over your backup protection strategy. Whether you want to use keys from the same account or across accounts, you maintain centralized key management while preserving the security benefits of logically air-gapped vaults. This integration works seamlessly with your existing logically air-gapped vaults and other AWS Backup features, ensuring no disruption to your backup workflows.
AWS KMS customer managed key support with logically air-gapped vaults is available in all AWS Regions where logically air-gapped vaults are [currently supported](https://docs.aws.amazon.com/aws-backup/latest/devguide/backup-feature-availability.html#features-by-region).
You can get started with logically air-gapped vault support for CMKs using the AWS Backup console, API, or CLI. When creating a new logically air-gapped vault, you can now choose between an AWS-owned key or your own CMK for encryption. For more information about implementing this feature, visit the AWS Backup [product page](https://aws.amazon.com/backup/faqs/), [documentation](https://docs.aws.amazon.com/aws-backup/latest/devguide/logicallyairgappedvault.html), and [blog](https://aws.amazon.com/blogs/storage/encrypt-aws-backup-logically-air-gapped-vaults-with-customer-managed-keys/).
What else is happening at Amazon Web Services?
Amazon SageMaker launches custom tags for project resources
about 9 hours ago
Services
Share
Read update
Services
Share
Read update
Services
Share
Amazon ECS announces non-root container support for managed EBS volumes
about 12 hours ago
Services
Share
Amazon Keyspaces (for Apache Cassandra) is now available in the Middle East (UAE) Region
about 12 hours ago
Services
Share
Read update
Services
Share