github.com/aquasecurity/trivy-iac@v0.8.1-0.20240127024015-3d8e412cf0ab/avd_docs/aws/s3/AVD-AWS-0132/CloudFormation.md (about) 1 2 Enable encryption using customer managed keys 3 4 ```yaml 5 Resources: 6 GoodExample: 7 Properties: 8 BucketEncryption: 9 ServerSideEncryptionConfiguration: 10 - BucketKeyEnabled: true 11 ServerSideEncryptionByDefault: 12 KMSMasterKeyID: kms-arn 13 SSEAlgorithm: aws:kms 14 Type: AWS::S3::Bucket 15 16 ``` 17 18