Skip to main content
compliance · aws

SageMaker notebook instances whose ML volume has no customer managed KMS key

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a SageMaker notebook instance created without a `KmsKeyId`, so its OS and ML data volumes are encrypted with a system-managed key instead of a key you control. The key can only be set when the notebook is created, which makes the fix a rebuild. The finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates SageMaker notebook instances whose ML volume has no customer managed KMS key.
Field Value
Rule IDsRC-1618
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdKmsKeyId empty
SourceZopNight
Permissions usedsagemaker:ListNotebookInstances · sagemaker:DescribeNotebookInstance

What sits on a notebook’s volume

A notebook instance keeps its notebooks, downloaded datasets, cached credentials in configuration files and intermediate results on its ML storage volume, which persists across stops. That volume is always encrypted, but if you do not specify a KMS key, SageMaker encrypts both the OS and ML data volumes with a system-managed key.

A customer managed key changes who is in charge. You write its key policy, CloudTrail logs every use, and disabling the key makes the volume unreadable. Many data-handling policies require that for any storage holding customer data.

Checking a notebook’s key

Terminal window
aws sagemaker describe-notebook-instance --notebook-instance-name my-notebook \
--query 'KmsKeyId'

null means the notebook was created without a customer managed key.

Basis for the finding

ZopNight records the KMS key field for every notebook instance. It flags an InService notebook when the field is present and empty, which is the confirmed “no key” state. A notebook whose record lacks the field entirely is not flagged.

Limits of the check

The rule confirms only that a key was specified, not which one, so any key passes, including one with a permissive key policy. It also covers only the notebook’s own volume; data in S3 buckets the notebook reads is governed by the bucket’s encryption, which Resource Not Encrypted At Rest looks at.

Key custody, not cost

ZopNight attaches a $0 saving. The added cost is small: a monthly charge per customer managed key and KMS request charges when the volume is used.

Rebuilding the notebook with your own key

update-notebook-instance has no option for the KMS key, so a new instance is needed:

  1. Create or choose a customer managed key and allow the notebook’s execution role to use it.
  2. Copy notebooks and data off the old instance to S3 or Git.
  3. Create the replacement with the key:
Terminal window
aws sagemaker create-notebook-instance --notebook-instance-name my-notebook-cmk \
--instance-type ml.t3.medium --role-arn arn:aws:iam::111122223333:role/SageMakerRole \
--kms-key-id arn:aws:kms:us-east-1:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab
  1. Restore the files, confirm the new notebook works, then delete the old instance.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·