AWSHow-To & HardeningRetrospectives

S3 Encryption and KMS Key Policy Audit Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.

KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.

S3 encryption

  • Default encryption configured on every bucket (SSE-S3 minimum; SSE-KMS for sensitive buckets).
  • S3 Bucket Keys enabled for SSE-KMS buckets.
  • Bucket policies deny uploads without the required encryption where needed.
  • SSE-C blocked where not used.
  • Older unencrypted objects identified (S3 Inventory reports encryption status) and re-encrypted if required.

KMS key policies

  • Each customer managed key has a named owner.
  • Key administrators (who can change policy, schedule deletion) are separate from key users (who can encrypt/decrypt).
  • No key policy grants kms:* to broad principals.
  • Cross-account access to keys is explicit and documented.
  • The root account principal statement is understood (it delegates to IAM policies).
  • Key rotation enabled for symmetric customer managed keys.

Deletion protection

  • Scheduled key deletion requires a waiting period (7–30 days).
  • Alerts fire on ScheduleKeyDeletion and DisableKey.
  • SCPs restrict key deletion to a break-glass role.

Monitoring

  • CloudTrail logs KMS Decrypt events for sensitive keys.
  • Unusual decrypt volume or new principals trigger review.

Review

  • Key policies reviewed annually and when teams change.
kms key policy audit checklistS3 default encryption2023

More on this story