This is a dedicated watch page for a single video.
A developer is using AWS KMS to encrypt sensitive application data. The developer wants to ensure that only specific AWS IAM users and roles have the ability to use the KMS key for encryption and decryption. How can the developer enforce this?