DocumentDB encryption should use Customer Managed Keys
Using AWS managed keys does not allow for fine grained control. Encryption using AWS keys provides protection for your DocumentDB underlying storage. To increase control of the encryption and manage factors like rotation use customer managed keys.
Impact
Recommended Actions
Follow the appropriate remediation steps below to resolve the issue.