Medium
DocumentDB
Regional
Amazon DocumentDB clusters should be encrypted at rest
NIST 800-53ISO 27001HIPAA
Description
Verifies that DocumentDB clusters are encrypted at rest using AES-256 with encryption keys managed by AWS KMS.
Remediation
Enable encryption at rest for your Amazon DocumentDB clusters. You cannot enable encryption at rest for an existing cluster, so you must create a new cluster with encryption enabled.
Steps
- Open the Amazon DocumentDB console.
- Choose 'Clusters' from the navigation pane.
- Create a new cluster or modify an existing one.
- In the 'Encryption' section, select 'Enable encryption'.
- Choose an AWS KMS key (either AWS managed or customer managed).
- Complete the cluster creation or modification process.
Compliance
NIST 800-53ISO 27001HIPAA