Medium ECR Regional

ECR repositories should be encrypted with customer managed AWS KMS keys

NIST 800-53

Description

Verifies that ECR repositories are encrypted at rest with a customer managed KMS key.


Remediation

To enable customer managed KMS encryption for your ECR repository, you need to configure the encryption settings when creating or updating the repository.

Steps

  1. Navigate to the Amazon ECR console
  2. Select the repository you want to configure
  3. Choose 'Edit' and go to 'Encryption settings'
  4. Select 'KMS' as the encryption type
  5. Choose a customer managed KMS key from the dropdown
  6. Save the changes to apply the encryption settings

Compliance

NIST 800-53