Medium Kinesis Regional

Firehose delivery streams should be encrypted at rest

NIST 800-53

Description

Ensures Firehose delivery streams are encrypted at rest using AWS KMS. Data is encrypted before being written to the stream's storage layer and decrypted on retrieval, supporting regulatory compliance.


Remediation

Enable server-side encryption for your Amazon Data Firehose delivery streams using AWS KMS.

Steps

  1. Navigate to the Amazon Kinesis Data Firehose console
  2. Select the delivery stream that needs encryption
  3. Edit the delivery stream configuration
  4. In the 'Encryption' section, enable 'Server-side encryption'
  5. Choose 'AWS KMS' as the encryption key source
  6. Select or create a KMS key for encryption
  7. Save the configuration changes
  8. Verify that the delivery stream is now encrypted at rest

Compliance

NIST 800-53