Medium DMS Regional

DMS endpoints for Redis OSS should have TLS enabled

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA

Description

Ensures AWS DMS endpoints for Redis OSS use TLS connections, encrypting data in transit to prevent eavesdropping during migration.


Remediation

Configure your DMS endpoints for Redis OSS to use TLS encryption. Set the SSL mode to 'require', 'verify-ca', or 'verify-full'.

Steps

  1. Open the AWS DMS console.
  2. In the navigation pane, choose 'Endpoints'.
  3. Select the Redis endpoint you want to modify.
  4. Choose 'Actions' and then 'Modify'.
  5. In the 'Endpoint settings' section, set 'SSL mode' to 'require', 'verify-ca', or 'verify-full'.
  6. Choose 'Continue' and then 'Modify endpoint'.

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA