The document outlines various methods for encrypting data at rest within Amazon Web Services (AWS) to meet organizational security policies and regulations. It describes three models of encryption control regarding who manages keys and encryption methods, ranging from full user control to AWS-managed solutions. The paper further details specific AWS services like Amazon S3, EBS, RDS, and additional encryption tools to protect data effectively while ensuring key management is secure.