Medium
DMS
Regional
DMS endpoints should use SSL
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA
Description
Confirms that AWS DMS endpoints use SSL connections, encrypting data in transit and validating the target database's server certificate during migration.
Remediation
Enable SSL connections for your DMS endpoints to encrypt data in transit during database migration.
Steps
- Navigate to the AWS DMS console
- Go to the Endpoints section
- Select the endpoint that needs SSL enabled
- Modify the endpoint configuration
- In the 'SSL mode' section, select an SSL mode other than 'none'
- Choose appropriate SSL mode: 'require', 'verify-ca', or 'verify-full'
- Configure SSL certificate if needed
- Save the configuration changes
- Verify that SSL is now enabled for the endpoint
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA