A media production company maintains a centralized AWS account to aggregate logs and telemetry from multiple sources. These logs are stored in Amazon S3 buckets. To comply with internal data security policies, a solutions architect must ensure that all incoming data is encrypted before it reaches S3 and that it remains protected during transfer. What is the best way to meet both the encryption at rest and in transit requirements?