Service provides centralized control over cryptographic keys with with automatic rotation and audit logging. Customer Managed Full control, rotation, deletion AWS Managed Automatic, service-integrated ENCRYPTION AT REST Amazon S3 SSE-KMS, SSE-S3, or client-side encryption. Enable S3 Bucket Keys for 10-1000x cost improvement. improvement. Amazon RDS Enable encryption at launch using KMS keys. Encrypts underlying storage, backups, and snapshots. Amazon EBS Encrypt volumes during creation. All snapshots and AMIs encrypted automatically. ENCRYPTION IN TRANSIT TLS/SSL Everywhere Enforce HTTPS-only connections. Use ACM for certificate management. VPC Endpoints Private connectivity to AWS services without traversing public internet. AWS Certificate Manager Provision, manage, and deploy SSL/TLS certificates automatically. SECRETS MANAGEMENT AWS Secrets Manager Rotate, manage, retrieve credentials. Automatic rotation for RDS. Parameter Store Secure hierarchical storage for config data and secrets. Free for standard. KEY BEST PRACTICES Enable automatic key rotation Use customer-managed keys for sensitive data Monitor KMS usage with CloudTrail CloudTrail Implement least privilege key policies