Medium Elasticsearch Regional

Elasticsearch domains should encrypt data sent between nodes

NISTISO 27001

Description

This check ensures that Elasticsearch domains have node-to-node encryption enabled, securing data in transit between nodes within the domain.


Remediation

To enable node-to-node encryption for an Elasticsearch domain, follow these steps:

Steps

  1. Open the Amazon Elasticsearch Service console at https://console.aws.amazon.com/es/.
  2. Choose the domain that you want to modify.
  3. In the navigation pane, under Domain configuration, choose Node-to-node encryption.
  4. Select Enable for Node-to-node encryption.
  5. Choose Save changes.

Compliance

NISTISO 27001