Medium DocumentDB Regional

Amazon DocumentDB clusters should be encrypted at rest

NIST 800-53ISO 27001HIPAA

Description

Verifies that DocumentDB clusters are encrypted at rest using AES-256 with encryption keys managed by AWS KMS.


Remediation

Enable encryption at rest for your Amazon DocumentDB clusters. You cannot enable encryption at rest for an existing cluster, so you must create a new cluster with encryption enabled.

Steps

  1. Open the Amazon DocumentDB console.
  2. Choose 'Clusters' from the navigation pane.
  3. Create a new cluster or modify an existing one.
  4. In the 'Encryption' section, select 'Enable encryption'.
  5. Choose an AWS KMS key (either AWS managed or customer managed).
  6. Complete the cluster creation or modification process.

Compliance

NIST 800-53ISO 27001HIPAA