Medium
CodeBuild
Regional
CodeBuild report group exports should be encrypted at rest
FSBP
Description
This control checks whether the test results of an AWS CodeBuild report group that are exported to an Amazon Simple Storage Service (Amazon S3) bucket are encrypted at rest. The control fails if the report group export isn't encrypted at rest. Data at rest refers to data that's stored in persistent, non-volatile storage for any duration. Encrypting data at rest helps you protect its confidentiality, which reduces the risk that an unauthorized user can access it.
Remediation
Enable encryption at rest for your CodeBuild report group exports to S3.
Steps
- Navigate to the CodeBuild console
- Go to the Report groups section
- Select the report group that needs encryption
- Edit the report group configuration
- In the export configuration, ensure encryption is enabled
- Configure the S3 destination with encryption settings
- Save the configuration changes
- Verify that exports are now encrypted at rest
Compliance
FSBP