Protect Data at Rest
Enable encryption - KMS & Cloud HSM (Rotate encryption keys)
Enable versioning (when available)
Protect Data in Transit
Data coming in and going out of AWS
By default, all AWS API use HTTPS/SSL
You can also choose to perform client side encryption for additional security
Ensure your data stays in AWS network when possible (VPC Endpoints and AWS
PrivateLink)