> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-187.md).

# AWS Sagemaker domain not encrypted using Customer Managed Key misconfiguration detected in code

## Rule Details

|                        |                           |
| ---------------------- | ------------------------- |
| Cortex AppSec Rule ID  | APPSEC\_AWS\_187          |
| Category - Subcategory | Storage - Encryption      |
| Provider               | AWS                       |
| Severity               | LOW                       |
| Framework              | Terraform, Terraform Plan |

## Impact

Amazon SageMaker Feature Store enables you to create two types of stores: an online store or offline store. The online store is used for low latency real-time inference use cases whereas the offline store is used for training and batch inference use cases. When you create a feature group for online or offline use you can provide a AWS Key Management Service customer managed key to encrypt all your data at rest. In case you do not provide a AWS KMS key then we ensure that your data is encrypted on the server side using an AWS owned AWS KMS key or AWS managed AWS KMS key.

## How to Fix

To fix this issue, ensure that the `kms_key_id` property in the `aws_sagemaker_domain` resource is set to a valid KMS key ARN or key ID.

*CloudFormation*

To fix this issue, ensure that the `KmsKeyId` property in the `AWS::SageMaker::NotebookInstance` or `AWS::SageMaker::Domain` resource is set to a valid KMS key ARN or key ID.

Example for a SageMaker Notebook Instance:

## Example for a SageMaker Domain: \[source,go]

resource "aws\_sagemaker\_domain" "example" { ...

* kms\_key\_id = "ckv\_kms" }

***

## Resources: MySagemakerNotebookInstance: Type: AWS::SageMaker::NotebookInstance Properties: ... KmsKeyId: arn:aws:kms:us-west-2:123456789012:key/example-key-arn ...

## Resources: MySagemakerDomain: Type: AWS::SageMaker::Domain Properties: ... KmsKeyId: arn:aws:kms:us-west-2:123456789012:key/example-key-arn ...


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-187.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
