Medium
ECR
Regional
ECR repositories should be encrypted with customer managed AWS KMS keys
NIST 800-53
Description
Verifies that ECR repositories are encrypted at rest with a customer managed KMS key.
Remediation
To enable customer managed KMS encryption for your ECR repository, you need to configure the encryption settings when creating or updating the repository.
Steps
- Navigate to the Amazon ECR console
- Select the repository you want to configure
- Choose 'Edit' and go to 'Encryption settings'
- Select 'KMS' as the encryption type
- Choose a customer managed KMS key from the dropdown
- Save the changes to apply the encryption settings
Compliance
NIST 800-53