AWS – AWS Control Tower now provides support for KMS Encryption
Today, we are announcing new functionality in AWS Control Tower that provides you the option to use a single customer provided AWS Key Management Service (AWS KMS) key to secure the AWS Control Tower deployed services (AWS CloudTrail, AWS Config) and the associated AWS S3 data. The use of AWS KMS encryption gives you enhanced encryption over the default SSE-S3 encryption used by AWS Control Tower.
Read More for the details.