When a user creates a database instance from Relational Database Service (RDS), the user can select Disk encryption and use the key provided by KMS to encrypt the disk of the database instance. For more information, see the Relational Database Service User Guide.Figure 1 Encrypting data in RDS
You can use a custom key created on the KMS console for encryption.