Security
When you build systems on AWS infrastructure, security
responsibilities are shared between you and AWS. This
shared
responsibility model
IAM roles
AWS Identity and Access Management
AWS Key Management Service
This solution creates two
AWS Key Management Service
-
One of the keys is used to encrypt objects in the S3 artifact and source code buckets, and CodeBuild projects.
-
The second key is used to encrypt the Network Firewall log destinations, which depends on whether you select
Amazon CloudWatch
orAmazon S3 bucket
for the Select the type of log destination for the Network Firewall parameter.
By default, only IAM roles provisioned by this solution have permission to perform encrypt or decrypt operations with this key. Automatic key rotation is enabled by default.