Amazon Web Services (AWS) is a Seattle-headquartered cloud provider originally created to standardize the infrastructure behind Amazon’s retail operations, then launched as a subscription-based platform in 2006. It has become the largest cloud provider by infrastructure footprint and revenue, operating 60 availability zones across 20 regions and serving customers worldwide. AWS positions itself as a platform for “builders,” offering hundreds of services from core infrastructure to advanced capabilities like machine learning and satellite management.
As cloud adoption grows, so does the volume of sensitive data stored and processed in the cloud, making confidentiality, integrity, and availability a central operational, security, and compliance challenge. Under the shared responsibility model, customers remain responsible for protecting their data regardless of the cloud service model. Encryption remains the dominant method for protecting data at rest and in transit, but organizations then face the operational burden of managing numerous encryption keys and certificates across disparate systems.
AWS addresses this through managed services: AWS Key Management Service (KMS), AWS Certificate Manager (ACM), and AWS CloudHSM. KMS centralizes key creation, policy control, rotation, lifecycle actions, and auditing via CloudTrail, and is backed by FIPS 140-2 certified HSM infrastructure abstracted from customers. Its core object is the Customer Master Key (CMK), commonly used to generate data encryption keys (DEKs) that encrypt actual data. AWS distinguishes AWS-owned, AWS-managed, and customer-managed CMKs, with only customer-managed keys providing full customer control and incurring KMS monthly fees. For stricter requirements, KMS can use a single-tenant custom key store backed by CloudHSMv2, though it cannot connect to on-premises HSMs for HYOK scenarios. ACM automates TLS certificate provisioning, validation (including Route 53 automation), deployment, and renewal for Amazon-issued certificates, integrates broadly across AWS services at no added charge, and can extend to private certificates via ACM Private CA.
See All Locations
See All Locations