Encryption and decryption
The team has now acquired a more complete knowledge of IAM, their identities, their policies, and how they can be used to grant or deny permissions to diverse resources. But a final consideration has to be made – encryption, which is not done by IAM:

Alex: I’d like to end the day with a very short description of encryption. Most data can be encrypted; sometimes, it is even mandatory, but it will be performed automatically, without you noticing it.

Harold: Are you talking about encryption in transit or encryption at rest?

Alex: With many of the services in AWS, you can choose both.

Raj: I assume encryption is not provided by IAM. I didn’t see that on the documentation, and it seems a different feature. Probably a separate service?

Alex: It is called KMS, short for Key Management Service.
