Security - Customizations for AWS Control Tower


When you build systems on AWS infrastructure, security responsibilities are shared between you and AWS. This shared model can reduce your operational burden as AWS operates, manages, and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the services operate. For more information about security on AWS, visit the AWS Security Center.

AWS Key Management Service

Customizations for AWS Control Tower creates an AWS Key Management Service (AWS KMS) CustomControlTowerKMSKey encryption key. This key is used to encrypt objects in the Amazon Simple Storage Service (Amazon S3) configuration bucket, Amazon Simple Queue Service (Amazon SQS) FIFO queue, and sensitive parameters in the AWS Systems Manager Parameter Store.