Amazon OpenSearch Service now supports index-level encryption
Amazon Web Services has introduced index-level encryption for its OpenSearch Service, allowing organizations to encrypt data at rest on a per-index basis using AWS Key Management Service customer managed keys. The new capability enables users to apply different customer managed keys to different indexes within the same domain, providing more granular and tenant-specific encryption policies than the existing domain-level encryption approach. The feature builds upon OpenSearch Service's existing encryption at rest functionality, which previously used a single AWS KMS key to encrypt all data on a domain. With index-level encryption, administrators can now register KMS keys through the Amazon OpenSearch Service API and specify the key ARN in index settings when creating encrypted indexes. This isolation of encrypted data across indexes addresses compliance and security requirements for multi-tenant environments where different data sets require separate encryption controls. Index-level encryption is available at no additional cost for Amazon OpenSearch Service domains running OpenSearch version 3.3 or later, and has been rolled out across 14 AWS regions including major markets in North America, Europe, South America, and Asia Pacific.
Why It Matters
This enhancement addresses a critical security gap for organizations using OpenSearch Service in multi-tenant environments or with strict data isolation requirements. The ability to apply granular encryption policies at the index level enables better compliance with regulations like GDPR, HIPAA, and industry-specific standards that require tenant-specific data protection. This feature particularly benefits SaaS providers, enterprises with multiple business units, and organizations handling data with varying sensitivity levels who previously had to choose between operational efficiency and security granularity.
This summary is generated using AI analysis of the original press release. Always refer to the original source for complete details.