Medium
Elasticsearch
Regional
Elasticsearch domains should encrypt data sent between nodes
NISTISO 27001
Description
Ensures Elasticsearch domains have node-to-node encryption enabled, securing data in transit within the cluster.
Remediation
To enable node-to-node encryption for an Elasticsearch domain, follow these steps:
Steps
- Open the Amazon Elasticsearch Service console at https://console.aws.amazon.com/es/.
- Choose the domain that you want to modify.
- In the navigation pane, under Domain configuration, choose Node-to-node encryption.
- Select Enable for Node-to-node encryption.
- Choose Save changes.
Compliance
NISTISO 27001