Medium DMS Regional

DMS endpoints should use SSL

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA

Description

Confirms that AWS DMS endpoints use SSL connections, encrypting data in transit and validating the target database's server certificate during migration.


Remediation

Enable SSL connections for your DMS endpoints to encrypt data in transit during database migration.

Steps

  1. Navigate to the AWS DMS console
  2. Go to the Endpoints section
  3. Select the endpoint that needs SSL enabled
  4. Modify the endpoint configuration
  5. In the 'SSL mode' section, select an SSL mode other than 'none'
  6. Choose appropriate SSL mode: 'require', 'verify-ca', or 'verify-full'
  7. Configure SSL certificate if needed
  8. Save the configuration changes
  9. Verify that SSL is now enabled for the endpoint

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA