Medium
DMS
Regional
DMS endpoints for Redis OSS should have TLS enabled
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA
Description
Ensures AWS DMS endpoints for Redis OSS use TLS connections, encrypting data in transit to prevent eavesdropping during migration.
Remediation
Configure your DMS endpoints for Redis OSS to use TLS encryption. Set the SSL mode to 'require', 'verify-ca', or 'verify-full'.
Steps
- Open the AWS DMS console.
- In the navigation pane, choose 'Endpoints'.
- Select the Redis endpoint you want to modify.
- Choose 'Actions' and then 'Modify'.
- In the 'Endpoint settings' section, set 'SSL mode' to 'require', 'verify-ca', or 'verify-full'.
- Choose 'Continue' and then 'Modify endpoint'.
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA