---
title: MSK clusters should be encrypted with a customer-managed KMS key
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > MSK clusters should be encrypted with a
  customer-managed KMS key
---

# MSK clusters should be encrypted with a customer-managed KMS key
 
## Description{% #description %}

MSK clusters should be encrypted using a customer-managed KMS key for data volumes rather than the default AWS-managed key. Customer-managed keys provide full control over key rotation policies, access permissions via KMS key policies, and the ability to revoke or disable the key.

## Remediation{% #remediation %}

Create a new MSK cluster with a customer-managed KMS key specified for data volume encryption. Existing clusters cannot have their encryption key changed after creation. For guidance, refer to [Amazon MSK encryption](https://docs.aws.amazon.com/msk/latest/developerguide/msk-encryption.html).
