Medium APIGateway Regional

API Gateway REST API cache data should be encrypted at rest

NISTISO 27001

Description

This control checks whether API Gateway REST API stages with cache enabled have the cache data encrypted at rest.


Remediation

To encrypt cache data for API Gateway REST API stages, enable cache encryption in the stage settings.

Steps

  1. Navigate to the API Gateway console.
  2. Select the API and stage you want to configure.
  3. In Cache Settings, choose 'Encrypt cache data'.

Compliance

NISTISO 27001